Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-4623
Description:The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.866917   1.3.6.1.4.1.25623.1.0.702782  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-4623
BugTraq ID: 61764
http://www.securityfocus.com/bid/61764
Debian Security Information: DSA-2782 (Google Search)
http://www.debian.org/security/2013/dsa-2782
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116351.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115922.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115927.html




© 1998-2025 E-Soft Inc. All rights reserved.