|Summary:||CVE-2014-4911 PolarSSL: Denial of Service against GCM enabled servers (and clients)|
|Product:||[Other] Security Response||Reporter:||Kurt Seifried <kseifried>|
|Component:||vulnerability||Assignee:||Red Hat Product Security <security-response-team>|
|Status:||CLOSED ERRATA||QA Contact:|
|Version:||unspecified||CC:||carnil, mads, mstevens|
|Fixed In Version:||Doc Type:||Bug Fix|
|Doc Text:||Story Points:||---|
|Last Closed:||2015-09-05 18:56:35 UTC||Type:||---|
|oVirt Team:||---||RHEL 7.3 requirements from Atomic Host:|
|Bug Depends On:||1118930, 1118931|
Description Kurt Seifried 2014-07-12 01:15:55 UTC
Offspark B.V. reports: PolarSSL Security Advisory 2014-02 Title Denial of Service against GCM enabled servers (and clients) CVE CVE-2014-4911 Date 11th of July 2014 Affects All PolarSSL versions before 1.2.11 and 1.3.8 Not affected All branches before 1.2.x and version > 1.2.10 or > 1.3.7 Impact Crash of server application (or clients by a malicious server) Exploit Withheld A denial of service against PolarSSL servers that offer GCM ciphersuites has been found using the fuzzing techniques of the Codenomicon Defensics toolkit. Potentially clients are affected too if a malicious server decides to execute the denial of service attack against its clients. Impact A server or client that is targeted with this attack can be potentially crashed with a segfault. Workaround Disabling of the GCM ciphersuites prevents this attack. Patch See External Reference External reference: https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-02
Comment 1 Kurt Seifried 2014-07-12 01:17:37 UTC
Created polarssl tracking bugs for this issue: Affects: epel-all [bug 1118931]
Comment 2 Fedora Update System 2014-07-22 03:29:23 UTC
polarssl-1.2.11-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
Comment 3 Fedora Update System 2014-07-22 03:29:36 UTC
polarssl-1.2.11-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2014-07-30 19:35:22 UTC
polarssl-1.3.2-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2014-07-30 19:35:30 UTC
polarssl-1.3.2-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.