4
CVSSv2

CVE-2011-1923

Published: 20/06/2012 Updated: 24/10/2013
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL prior to 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle malicious users to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095.

Vulnerable Product Search on Vulmon Subscribe to Product

polarssl polarssl 0.10.1

polarssl polarssl 0.10.0

polarssl polarssl

polarssl polarssl 0.11.1

polarssl polarssl 0.11.0

polarssl polarssl 0.13.1

polarssl polarssl 0.12.1

polarssl polarssl 0.12.0

Vendor Advisories

Debian Bug report logs - #704946 polarssl: CVE-2009-3555 Package: polarssl; Maintainer for polarssl is Roland Stigge <stigge@antcomde>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Mon, 8 Apr 2013 02:39:02 UTC Severity: important Tags: security Fixed in version polarssl/131-1 Done: Roland Stigge &lt ...