Vulnerability Description
Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session, a different vulnerability than CVE-2013-0169.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Polarssl | Polarssl | <= 1.2.4 |
Related Weaknesses (CWE)
References
- http://openwall.com/lists/oss-security/2013/02/05/24
- http://www.debian.org/security/2013/dsa-2622
- http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
- https://polarssl.org/tech-updates/releases/polarssl-1.2.5-releasedPatchVendor Advisory
- http://openwall.com/lists/oss-security/2013/02/05/24
- http://www.debian.org/security/2013/dsa-2622
- http://www.isg.rhul.ac.uk/tls/TLStiming.pdf
- https://polarssl.org/tech-updates/releases/polarssl-1.2.5-releasedPatchVendor Advisory
FAQ
What is CVE-2013-1621?
CVE-2013-1621 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC pad...
How severe is CVE-2013-1621?
CVE-2013-1621 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1621?
Check the references section above for vendor advisories and patch information. Affected products include: Polarssl Polarssl.