Security Advisory

CVE-2013-4623

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2013-09-30 20:00:00
Last updated 2024-08-06 16:52:26
Assigner mitre
State PUBLISHED

Description

The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.