PT-2021-8355 · Polarssl · Polarssl

Published

2021-10-27

·

Updated

2021-10-28

·

CVE-2011-4574

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PolarSSL versions prior to v1.1
Description The issue concerns the use of the HAVEGE random number generation algorithm, which relies on timing information from the processor's high resolution timer, specifically the RDTSC instruction. This instruction can be virtualized, and some virtual machine hosts may disable it, resulting in predictable or zero returns.
Recommendations For PolarSSL versions prior to v1.1, consider updating to version v1.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of the HAVEGE random number generation algorithm until a patch is available. Restrict access to virtualized environments where the RDTSC instruction may be disabled to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4574

Affected Products

Polarssl