CVE-2014-4911
published 2014-07-22CVE-2014-4911: The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash)…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.43%
82.4th percentile
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| polarssl | polarssl | <= 1.2.10 | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
| polarssl | polarssl | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients)
bugzilla·2014-07-12·CVSS 5.0
CVE-2014-4911 [MEDIUM] CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients)
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients)
Offspark B.V. reports:
PolarSSL Security Advisory 2014-02
Title Denial of Service against GCM enabled servers (and clients)
CVE CVE-2014-4911
Date 11th of July 2014
Affects All PolarSSL versions before 1.2.11 and 1.3.8
Not affected All branches before 1.2.x and version > 1.2.10 or > 1.3.7
Impact Crash of server application (or clients by a malicious server)
Exploit Withheld
A denial of service against PolarSSL servers that offer GCM ciphersuites has been found using the fuzzing techniques of the Codenomicon Defensics toolkit. Potentially clients are affected too if a malicious server decides to execute the denial of service attack against its clients.
Impact
A server or client that is targeted with this
Bugzilla
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [fedora-all]
bugzilla·2014-07-12·CVSS 5.0
CVE-2014-4911 [MEDIUM] CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [fedora-all]
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issu
Bugzilla
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [epel-all]
bugzilla·2014-07-12·CVSS 5.0
CVE-2014-4911 [MEDIUM] CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [epel-all]
CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this i
http://secunia.com/advisories/60215http://www.debian.org/security/2014/dsa-2981https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-02http://secunia.com/advisories/60215http://www.debian.org/security/2014/dsa-2981https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-02
2014-07-22
Published