CVE-2014-4911
22.07.2014, 14:55
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.Enginsight
Vendor | Product | Version |
---|---|---|
polarssl | polarssl | 1.3.0 |
polarssl | polarssl | 1.3.0:alpha1 |
polarssl | polarssl | 1.3.0:rc0 |
polarssl | polarssl | 1.3.1 |
polarssl | polarssl | 1.3.2 |
polarssl | polarssl | 1.3.3 |
polarssl | polarssl | 1.3.4 |
polarssl | polarssl | 1.3.5 |
polarssl | polarssl | 1.3.6 |
polarssl | polarssl | 1.3.7 |
polarssl | polarssl | 𝑥 ≤ 1.2.10 |
polarssl | polarssl | 1.2.0 |
polarssl | polarssl | 1.2.1 |
polarssl | polarssl | 1.2.2 |
polarssl | polarssl | 1.2.3 |
polarssl | polarssl | 1.2.4 |
polarssl | polarssl | 1.2.5 |
polarssl | polarssl | 1.2.6 |
polarssl | polarssl | 1.2.7 |
polarssl | polarssl | 1.2.8 |
polarssl | polarssl | 1.2.9 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mbedtls |
| ||||||||||||||||||||||||||
polarssl |
|
Common Weakness Enumeration
References