Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfr2-452h-93q6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

EPSS

Процентиль: 78%
0.01887
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 13 лет назад

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

nvd
почти 13 лет назад

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

debian
почти 13 лет назад

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 an ...

fstec
почти 13 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 78%
0.01887
Низкий

Дефекты

CWE-20