Unrated severityNVD Advisory· Published Aug 24, 2015· Updated Jun 17, 2026
CVE-2014-8628
CVE-2014-8628
Description
Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.
Affected products
14cpe:2.3:a:polarssl:polarssl:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:polarssl:polarssl:*:*:*:*:*:*:*:*range: <=1.2.11
- cpe:2.3:a:polarssl:polarssl:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:polarssl:polarssl:1.3.8:*:*:*:*:*:*:*
- (no CPE)range: <1.2.12, >=1.3.0 <1.3.9
- osv-coords3 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Tumbleweed
< 2.28.3-1.1+ 2 more
- (no CPE)range: < 2.28.3-1.1
- (no CPE)range: < 3.6.6-1.1
- (no CPE)range: < 2.4.0-1.2
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.