CVE-2014-0625: Medium severity Dell BSAFE SSL-J vulnerability
The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0625?
CVE-2014-0625 has a medium severity rating due to its potential for causing denial of service through memory consumption.
How do I fix CVE-2014-0625?
To fix CVE-2014-0625, upgrade EMC RSA BSAFE SSL-J to version 5.1.3 or higher for 5.x versions, and to version 6.0.2 or higher for 6.x versions.
What systems are affected by CVE-2014-0625?
CVE-2014-0625 affects EMC RSA BSAFE SSL-J versions 5.0, 5.1.0, 5.1.1, 5.1.2 and 6.0, 6.0.1.
What type of attack does CVE-2014-0625 enable?
CVE-2014-0625 enables remote attackers to perform a denial of service attack by manipulating application-data processing during the TLS handshake.
Is CVE-2014-0625 easy to exploit?
Yes, CVE-2014-0625 can be easily exploited by remote attackers without the need for authentication.