The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-0656 The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during the TLS handshake, a time at which the data is internally buffered.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-06T09:20:19.705Z

Reserved: 2014-01-02T00:00:00

Link: CVE-2014-0625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-02-18T00:55:05.143

Modified: 2025-04-11T00:51:21.963

Link: CVE-2014-0625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses