MEDIUM · 5.0

CVE-2005-4839

PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.

Vulnerability Description

PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Claymore Systems IncPuretls<= 0.9b4

References

FAQ

What is CVE-2005-4839?

CVE-2005-4839 is a vulnerability with a CVSS score of 5.0 (MEDIUM). PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.

How severe is CVE-2005-4839?

CVE-2005-4839 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-4839?

Check the references section above for vendor advisories and patch information. Affected products include: Claymore Systems Inc Puretls.