4.3

CVE-2013-1621

Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session, a different vulnerability than CVE-2013-0169.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polarssl ≫ Polarssl Version <= 1.2.4
Polarssl ≫ Polarssl Version 0.10.0
Polarssl ≫ Polarssl Version 0.10.1
Polarssl ≫ Polarssl Version 0.11.0
Polarssl ≫ Polarssl Version 0.11.1
Polarssl ≫ Polarssl Version 0.12.0
Polarssl ≫ Polarssl Version 0.12.1
Polarssl ≫ Polarssl Version 0.13.1
Polarssl ≫ Polarssl Version 0.14.0
Polarssl ≫ Polarssl Version 0.14.2
Polarssl ≫ Polarssl Version 0.14.3
Polarssl ≫ Polarssl Version 0.99 Update pre1
Polarssl ≫ Polarssl Version 0.99 Update pre3
Polarssl ≫ Polarssl Version 0.99 Update pre4
Polarssl ≫ Polarssl Version 0.99 Update pre5
Polarssl ≫ Polarssl Version 1.0.0
Polarssl ≫ Polarssl Version 1.1.0
Polarssl ≫ Polarssl Version 1.1.0 Update rc0
Polarssl ≫ Polarssl Version 1.1.0 Update rc1
Polarssl ≫ Polarssl Version 1.1.1
Polarssl ≫ Polarssl Version 1.1.2
Polarssl ≫ Polarssl Version 1.1.3
Polarssl ≫ Polarssl Version 1.1.4
Polarssl ≫ Polarssl Version 1.1.5
Polarssl ≫ Polarssl Version 1.2.0
Polarssl ≫ Polarssl Version 1.2.1
Polarssl ≫ Polarssl Version 1.2.2
Polarssl ≫ Polarssl Version 1.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://openwall.com/lists/oss-security/2013/02/05/24
http://www.debian.org/security/2013/dsa-2622
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released
Patch
Vendor Advisory