Vulnerability Name: | CVE-2013-4623 (CCN-86381) | ||||||||||||||||||||||||
Assigned: | 2013-06-21 | ||||||||||||||||||||||||
Published: | 2013-06-21 | ||||||||||||||||||||||||
Updated: | 2013-10-31 | ||||||||||||||||||||||||
Summary: | The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4623 Source: FEDORA Type: UNKNOWN FEDORA-2013-16317 Source: FEDORA Type: UNKNOWN FEDORA-2013-16356 Source: FEDORA Type: UNKNOWN FEDORA-2013-16258 Source: CCN Type: PolarSSL Web site PolarSSL Source: CCN Type: SA54430 PolarSSL Certificate Message Processing Denial of Service Vulnerability Source: DEBIAN Type: UNKNOWN DSA-2782 Source: DEBIAN Type: DSA-2782 polarssl -- several vulnerabilities Source: BID Type: UNKNOWN 61764 Source: CCN Type: BID-61764 PolarSSL Certificate Message Remote Denial of Service Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 997767 (CVE-2013-4623) CVE-2013-4623 polarssl: denial of service (infinite loop) when parsing certain PEM encoded certificates Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=997767 Source: XF Type: UNKNOWN polarssl-cve20134623-dos(86381) Source: CONFIRM Type: Exploit, Patch https://github.com/polarssl/polarssl/commit/1922a4e6aade7b1d685af19d4d9339ddb5c02859 Source: CCN Type: PolarSSL Security Advisory 2013-03 Denial of Service through Certificate message during handshake Source: CONFIRM Type: Patch, Vendor Advisory https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2013-03 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |