CVE-2013-5915
- EPSS 0.69%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RSA-CRT implementation in PolarSSL before 1.2.9 does not properly perform Montgomery multiplication, which might allow remote attackers to conduct a timing side-channel attack and retrieve RSA private keys.
CVE-2013-4623
- EPSS 0.66%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU co...
CVE-2013-0169
- EPSS 1.08%
- Veröffentlicht 08.02.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding,...
CVE-2013-1621
- EPSS 0.88%
- Veröffentlicht 08.02.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session, a different vulnerability t...
- EPSS 0.36%
- Veröffentlicht 20.06.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a rel...