First published: Fri Dec 06 2019(Updated: )
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/polarssl | ||
PolarSSL | >=1.0.0<=1.1.1 | |
PolarSSL | =0.99-pre4 | |
PolarSSL | =0.99-pre5 | |
Debian | =8.0 | |
Fedora | =17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2130 is classified as a high severity vulnerability due to its potential to enable security bypass and unauthorized data access.
To fix CVE-2012-2130, upgrade PolarSSL to a version greater than 1.1.1 or apply any available patches from your software vendor.
CVE-2012-2130 affects PolarSSL versions from 0.99pre4 to 1.1.1 and specific distributions like Debian and Fedora.
CVE-2012-2130 is a security bypass vulnerability stemming from weak encryption in the generation of Diffie-Hellman values and RSA keys.
There are no specific workarounds for CVE-2012-2130, so updating the affected software is the recommended action.