FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-4623

This CVE name corresponds to:

Entered Topic
2013-08-13 polarssl -- denial of service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-4623
Phase Assigned(20130619)

Description

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

References

Source Reference
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=997767
CONFIRM https://github.com/polarssl/polarssl/commit/1922a4e6aade7b1d685af19d4d9339ddb5c02859
CONFIRM https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2013-03
DEBIAN DSA-2782
FEDORA FEDORA-2013-16258
FEDORA FEDORA-2013-16317
FEDORA FEDORA-2013-16356
BID 61764