7.8

CVE-2014-8628

Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates.  NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Polarssl ≫ Polarssl Version <= 1.2.11
Polarssl ≫ Polarssl Version 1.3.0
Polarssl ≫ Polarssl Version 1.3.1
Polarssl ≫ Polarssl Version 1.3.2
Polarssl ≫ Polarssl Version 1.3.3
Polarssl ≫ Polarssl Version 1.3.4
Polarssl ≫ Polarssl Version 1.3.5
Polarssl ≫ Polarssl Version 1.3.6
Polarssl ≫ Polarssl Version 1.3.7
Polarssl ≫ Polarssl Version 1.3.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.72% 0.745
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-updates/2014-11/msg00079.html
https://polarssl.org/tech-updates/releases/polarssl-1.3.9-released
http://www.debian.org/security/2014/dsa-3116
https://polarssl.org/tech-updates/releases/polarssl-1.2.12-released