4.3

CVE-2013-4623

Exploit
The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polarssl ≫ Polarssl Version 1.1.0
Polarssl ≫ Polarssl Version 1.1.0 Update rc0
Polarssl ≫ Polarssl Version 1.1.0 Update rc1
Polarssl ≫ Polarssl Version 1.1.1
Polarssl ≫ Polarssl Version 1.1.2
Polarssl ≫ Polarssl Version 1.1.3
Polarssl ≫ Polarssl Version 1.1.4
Polarssl ≫ Polarssl Version 1.1.5
Polarssl ≫ Polarssl Version 1.1.6
Polarssl ≫ Polarssl Version 1.2.0
Polarssl ≫ Polarssl Version 1.2.1
Polarssl ≫ Polarssl Version 1.2.2
Polarssl ≫ Polarssl Version 1.2.3
Polarssl ≫ Polarssl Version 1.2.4
Polarssl ≫ Polarssl Version 1.2.5
Polarssl ≫ Polarssl Version 1.2.6
Polarssl ≫ Polarssl Version 1.2.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115922.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115927.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116351.html
http://www.debian.org/security/2013/dsa-2782
http://www.securityfocus.com/bid/61764
https://bugzilla.redhat.com/show_bug.cgi?id=997767
https://github.com/polarssl/polarssl/commit/1922a4e6aade7b1d685af19d4d9339ddb5c02859
Patch
Exploit
https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2013-03
Patch
Vendor Advisory