4.3
CVSSv2

CVE-2013-5915

Published: 04/10/2013 Updated: 31/10/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The RSA-CRT implementation in PolarSSL prior to 1.2.9 does not properly perform Montgomery multiplication, which might allow remote malicious users to conduct a timing side-channel attack and retrieve RSA private keys.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

polarssl polarssl 0.10.0

polarssl polarssl 0.10.1

polarssl polarssl 0.14.3

polarssl polarssl 0.99

polarssl polarssl 1.1.0

polarssl polarssl 1.1.1

polarssl polarssl

polarssl polarssl 1.2.7

polarssl polarssl 0.12.0

polarssl polarssl 0.12.1

polarssl polarssl 0.13.1

polarssl polarssl 1.0.0

polarssl polarssl 1.1.4

polarssl polarssl 1.1.5

polarssl polarssl 1.2.3

polarssl polarssl 1.2.2

polarssl polarssl 0.14.0

polarssl polarssl 0.14.2

polarssl polarssl 1.1.6

polarssl polarssl 1.1.8

polarssl polarssl 1.2.1

polarssl polarssl 1.2.0

polarssl polarssl 0.11.0

polarssl polarssl 0.11.1

polarssl polarssl 1.1.2

polarssl polarssl 1.1.3

polarssl polarssl 1.2.6

polarssl polarssl 1.2.5

polarssl polarssl 1.2.4

Vendor Advisories

Multiple security issues have been discovered in PolarSSL, a lightweight crypto and SSL/TLS library: CVE-2013-4623 Jack Lloyd discovered a denial of service vulnerability in the parsing of PEM-encoded certificates CVE-2013-5914 Paul Brodeur and TrustInSoft discovered a buffer overflow in the ssl_read_record() function, allowing th ...
Debian Bug report logs - #719954 polarssl: CVE-2013-4623: Denial of Service through Certificate message during handshake Package: polarssl; Maintainer for polarssl is Roland Stigge <stigge@antcomde>; Reported by: Henri Salo <henri@nervfi> Date: Sat, 17 Aug 2013 07:42:01 UTC Severity: important Tags: fixed-upstream, ...
Debian Bug report logs - #704946 polarssl: CVE-2009-3555 Package: polarssl; Maintainer for polarssl is Roland Stigge <stigge@antcomde>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Mon, 8 Apr 2013 02:39:02 UTC Severity: important Tags: security Fixed in version polarssl/131-1 Done: Roland Stigge &lt ...
Debian Bug report logs - #725359 polarssl: CVE-2013-5914 CVE-2013-5915 Package: polarssl; Maintainer for polarssl is Roland Stigge <stigge@antcomde>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 4 Oct 2013 14:15:10 UTC Severity: grave Tags: pending, security Found in version 128-2 Fixed in version ...