MGASA-2014-0315
Dashboard / Vulnerabilities / MGASA-2014-0315
Summary: Updated polarssl packages fix security vulnerability
Details: A flaw was discovered in PolarSSL, a lightweight crypto and SSL/TLS library, which can be exploited by a remote unauthenticated attacker to mount a denial of service against PolarSSL servers that offer GCM ciphersuites. Potentially clients are affected too if a malicious server decides to execute the denial of service attack against its clients (CVE-2014-4911). The pdns package has been rebuilt against the updated polarssl library.
References: https://advisories.mageia.org/MGASA-2014-0315.html, https://bugs.mageia.org/show_bug.cgi?id=13764, https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-02, https://polarssl.org/tech-updates/releases/polarssl-1.3.8-released, https://www.debian.org/security/2014/dsa-2981
Affected packages
Package
Name: polarssl
Purl: pkg:rpm/mageia/polarssl?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
