CVE-2014-0625
Published Feb 18, 2014
Last updated 3 years ago
Overview
- Description
- The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
- Source
- security_alert@emc.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dell:bsafe_ssl-j:5.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "314CC197-7A5B-490E-BCA4-DCFFDC32A50F" }, { "criteria": "cpe:2.3:a:dell:bsafe_ssl-j:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "514F2922-83FA-4A51-BA74-A17175643BE6" }, { "criteria": "cpe:2.3:a:emc:rsa_bsafe_ssl-j:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B160FFB-EF0D-4D7B-9810-3D7728FB0B4C" }, { "criteria": "cpe:2.3:a:emc:rsa_bsafe_ssl-j:5.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "384C4C01-A2CF-4241-97D2-C379F4351DD0" }, { "criteria": "cpe:2.3:a:emc:rsa_bsafe_ssl-j:5.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB1CF0F5-828F-405C-B8E8-D7F8AD15BEF6" }, { "criteria": "cpe:2.3:a:emc:rsa_bsafe_ssl-j:6.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBF5DF8B-B891-4291-A5C2-91C2C2525F53" } ], "operator": "OR" } ] } ]