PT-2012-1170 · Openssl · Polarssl

Publicado

2012-06-20

·

Atualizado

2013-10-24

·

CVE-2011-1923

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions PolarSSL versions prior to 1.3.0 PolarSSL versions prior to 0.14.2
Description The issue concerns the Diffie-Hellman key-exchange implementation in PolarSSL, which does not properly validate a public parameter. This makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic. Multiple vulnerabilities in the PolarSSL package can lead to disruption of protected information and can be exploited remotely.
Recommendations For PolarSSL versions prior to 0.14.2, update to version 0.14.2 or later. For PolarSSL versions prior to 1.3.0, update to version 1.3.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09702
CVE-2011-1923

Produtos afetados

Polarssl