Offspark B.V. reports: PolarSSL Security Advisory 2014-02 Title Denial of Service against GCM enabled servers (and clients) CVE CVE-2014-4911 Date 11th of July 2014 Affects All PolarSSL versions before 1.2.11 and 1.3.8 Not affected All branches before 1.2.x and version > 1.2.10 or > 1.3.7 Impact Crash of server application (or clients by a malicious server) Exploit Withheld A denial of service against PolarSSL servers that offer GCM ciphersuites has been found using the fuzzing techniques of the Codenomicon Defensics toolkit. Potentially clients are affected too if a malicious server decides to execute the denial of service attack against its clients. Impact A server or client that is targeted with this attack can be potentially crashed with a segfault. Workaround Disabling of the GCM ciphersuites prevents this attack. Patch See External Reference External reference: https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-02
Created polarssl tracking bugs for this issue: Affects: epel-all [bug 1118931]
polarssl-1.2.11-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
polarssl-1.2.11-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
polarssl-1.3.2-2.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
polarssl-1.3.2-2.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.