Vulnerability Description
PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Claymore Systems Inc | Puretls | <= 0.9b4 |
References
- http://www.rtfm.com/puretls/
- http://www1.ietf.org/mail-archive/web/tls/current/msg00229.html
- http://www.rtfm.com/puretls/
- http://www1.ietf.org/mail-archive/web/tls/current/msg00229.html
FAQ
What is CVE-2005-4839?
CVE-2005-4839 is a vulnerability with a CVSS score of 5.0 (MEDIUM). PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.
How severe is CVE-2005-4839?
CVE-2005-4839 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4839?
Check the references section above for vendor advisories and patch information. Affected products include: Claymore Systems Inc Puretls.