CVE-2014-8627: Medium severity polarssl vulnerability
Published Nov 24, 2014
·Updated
PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
Affected Software
1 affected component
PolarSSL PolarSSL=1.3.8
Remediation
Event History
Nov 24, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8627?
CVE-2014-8627 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2014-8627?
To fix CVE-2014-8627, upgrade PolarSSL to version 1.3.9 or later.
3
What type of attack does CVE-2014-8627 allow?
CVE-2014-8627 allows remote attackers to conduct downgrade attacks.
4
Which version of PolarSSL is affected by CVE-2014-8627?
PolarSSL version 1.3.8 is affected by CVE-2014-8627.
5
What causes the vulnerability in CVE-2014-8627?
The vulnerability in CVE-2014-8627 is caused by improper negotiation of the signature algorithm.