CVE-2013-5914: Buffer Overflow
Published Oct 26, 2013
·Updated
Buffer overflow in the sslreadrecord function in ssltls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute arbitrary code via a long packet.
Affected Software
11 affected components
PolarSSL PolarSSL<=1.1.7
PolarSSL PolarSSL=1.0.0
PolarSSL PolarSSL=1.1.0
PolarSSL PolarSSL=1.1.0-rc0
PolarSSL PolarSSL=1.1.0-rc1
PolarSSL PolarSSL=1.1.1
PolarSSL PolarSSL=1.1.2
PolarSSL PolarSSL=1.1.3
PolarSSL PolarSSL=1.1.4
PolarSSL PolarSSL=1.1.5
PolarSSL PolarSSL=1.1.6
Remediation
Event History
Oct 26, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5914?
CVE-2013-5914 has a severity rating that indicates it could allow remote attackers to execute arbitrary code due to a buffer overflow.
2
How do I fix CVE-2013-5914?
To fix CVE-2013-5914, upgrade PolarSSL to version 1.1.8 or later.
3
Which versions of PolarSSL are affected by CVE-2013-5914?
CVE-2013-5914 affects PolarSSL versions up to 1.1.7 and specific earlier versions.
4
In what function does CVE-2013-5914 occur?
CVE-2013-5914 occurs in the ssl_read_record function within ssl_tls.c.
5
What attack vector is associated with CVE-2013-5914?
CVE-2013-5914 can be exploited via a long packet sent by remote attackers.