CVE-2014-4911
Published Jul 22, 2014
Last updated 9 years ago
Overview
- Description
- The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9400165F-7CA8-43B6-9C18-A9B68960C69D" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E55CFB7-DD01-49EB-87CC-B7CC76B2B638" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.0:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD884F2C-3E94-4815-A035-E1134E55991F" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F27E26E-D912-462A-AE70-90AA058B9DDF" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FEB54854-6DC9-44B9-A94A-671C17C1F0A9" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "495BE6FC-806F-489E-85EF-5F6CF3E6B068" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E56EC828-5984-4800-B366-3E3A2ED4A397" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC0A5B11-E428-4B81-8125-4C26DC42733F" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B085B300-6A08-4649-AB6A-167761D3138A" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1F43435-B2E1-4CF5-A7B7-0FD50C905783" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:polarssl:polarssl:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "963DEE80-E81A-4559-BBF9-4A7970F59A6A", "versionEndIncluding": "1.2.10" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CF482DF-9F5C-45D6-AA5E-D9163A710AAD" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5152886-DFBB-415C-99E0-A7E645A5F86B" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5BD989E-FC1D-44D2-9394-C36AD18325DE" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE349CDB-AE50-4043-86EF-1CED401AAEFC" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48FAB18E-F1C9-46B2-985E-28AC2736DB3F" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C453569-3736-4FC3-87FE-8282A1572CA3" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E86CC3C2-C0D0-420A-97FA-1862B9CF2CE0" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67CE5D3D-FE2C-403E-9A90-43CB04A96CD1" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "229B9538-A16D-4572-B9CA-5FA2E4B56D8A" }, { "criteria": "cpe:2.3:a:polarssl:polarssl:1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E3F98E8-E610-41BC-949A-09382B612D16" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "036E8A89-7A16-411F-9D31-676313BB7244" }, { "criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA" }, { "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43" } ], "operator": "OR" } ] } ]