CVE-2014-9744: High severity openSUSE openSUSE vulnerability
Published Aug 24, 2015
·Updated
Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions.
Affected Software
2 affected components
openSUSE openSUSE=13.2
PolarSSL PolarSSL<=1.3.8
Remediation
Event History
Aug 24, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9744?
CVE-2014-9744 is classified as a denial of service vulnerability due to memory consumption issues.
2
How do I fix CVE-2014-9744?
To fix CVE-2014-9744, update PolarSSL to version 1.3.9 or later.
3
Which versions of PolarSSL are affected by CVE-2014-9744?
CVE-2014-9744 affects all versions of PolarSSL prior to 1.3.9.
4
What types of attacks can exploit CVE-2014-9744?
Attackers can exploit CVE-2014-9744 by sending a large number of ClientHello messages to cause a denial of service.
5
Is CVE-2014-9744 fixed in openSUSE 13.2?
CVE-2014-9744 is not fixed in openSUSE 13.2, so users should ensure they are running an updated version.