Heap-based Buffer Overflow in PolarSSL and ARM mbed TLS Products
CVE-2015-5291
Currently unrated
Summary
A heap-based buffer overflow vulnerability exists in PolarSSL versions prior to 1.2.17 and ARM mbed TLS versions before 1.3.14 and 2.1.2. This flaw can be exploited by remote SSL servers through a malformed hostname sent in the Server Name Indication (SNI) extension of a ClientHello message. If successfully executed, it may lead to a denial of service by crashing the client application and could potentially allow for arbitrary code execution.
References
Timeline
Vulnerability published
Vulnerability Reserved