CVE-2014-4911: Medium severity polarssl vulnerability
Published Jul 22, 2014
·Updated
The ssldecryptbuf function in library/ssltls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.
Affected Software
24 affected components
PolarSSL PolarSSL=1.3.0
PolarSSL PolarSSL=1.3.0-alpha1
PolarSSL PolarSSL=1.3.0-rc0
PolarSSL PolarSSL=1.3.1
PolarSSL PolarSSL=1.3.2
PolarSSL PolarSSL=1.3.3
PolarSSL PolarSSL=1.3.4
PolarSSL PolarSSL=1.3.5
PolarSSL PolarSSL=1.3.6
PolarSSL PolarSSL=1.3.7
PolarSSL PolarSSL<=1.2.10
PolarSSL PolarSSL=1.2.0
PolarSSL PolarSSL=1.2.1
PolarSSL PolarSSL=1.2.2
PolarSSL PolarSSL=1.2.3
PolarSSL PolarSSL=1.2.4
PolarSSL PolarSSL=1.2.5
PolarSSL PolarSSL=1.2.6
PolarSSL PolarSSL=1.2.7
PolarSSL PolarSSL=1.2.8
PolarSSL PolarSSL=1.2.9
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Event History
Jul 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4911?
CVE-2014-4911 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2014-4911?
To mitigate CVE-2014-4911, update your PolarSSL version to 1.3.8 or later, or upgrade to the most recent release.
3
Which versions of PolarSSL are affected by CVE-2014-4911?
CVE-2014-4911 affects PolarSSL versions prior to 1.2.11 and 1.3.x before 1.3.8.
4
Can CVE-2014-4911 be exploited remotely?
Yes, CVE-2014-4911 can be exploited remotely by attackers using GCM ciphersuites.
5
Is there a specific toolkit associated with the exploitation of CVE-2014-4911?
CVE-2014-4911 has been demonstrated to be exploitable using the Codenomicon Defensics toolkit.