Heap-based Buffer Overflow in PolarSSL and ARM mbed TLS Products
CVE-2015-5291

Currently unrated

Key Information:

Vendor
Arm
Vendor
CVE Published:
2 November 2015

Summary

A heap-based buffer overflow vulnerability exists in PolarSSL versions prior to 1.2.17 and ARM mbed TLS versions before 1.3.14 and 2.1.2. This flaw can be exploited by remote SSL servers through a malformed hostname sent in the Server Name Indication (SNI) extension of a ClientHello message. If successfully executed, it may lead to a denial of service by crashing the client application and could potentially allow for arbitrary code execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.