CVE-2013-2125: Medium severity OpenBSD OpenSMTPD vulnerability
Published May 27, 2014
·Updated
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open.
Affected Software
1 affected component
OpenBSD OpenSMTPD<=5.3.1
Remediation
Event History
May 27, 2014
CVE Published
02:55 PM
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2125?
The severity of CVE-2013-2125 is classified as moderate, primarily due to the denial of service risk it poses.
2
How do I fix CVE-2013-2125?
To fix CVE-2013-2125, upgrade OpenSMTPD to version 5.3.2 or later.
3
What types of attacks does CVE-2013-2125 allow?
CVE-2013-2125 allows remote attackers to cause a denial of service by keeping SSL connections open.
4
Which versions of OpenSMTPD are affected by CVE-2013-2125?
OpenSMTPD versions prior to 5.3.2, specifically up to 5.3.1, are affected by CVE-2013-2125.
5
Is CVE-2013-2125 related to SSL session handling?
Yes, CVE-2013-2125 specifically involves improper handling of SSL sessions in OpenSMTPD.