Debian Security Advisory

DLA-129-1 polarssl -- LTS security update

Date Reported:
03 Jan 2015
Affected Packages:
polarssl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-8628.
More information:

It was discovered that a memory leak in parsing X.509 certificates may result in denial of service.

For Debian 6 Squeeze, these issues have been fixed in polarssl version 1.2.9-1~deb6u3