Heap-based Buffer Overflow in ARM mbed TLS by PolarSSL
CVE-2015-8036

Currently unrated

Key Information:

Vendor
Arm
Vendor
CVE Published:
2 November 2015

Summary

A heap-based buffer overflow vulnerability exists in ARM mbed TLS (formerly PolarSSL) versions prior to 1.3.14 and 2.1.2. This flaw can be exploited by remote SSL servers that send a specially crafted long session ticket name in the session ticket extension, at which point the vulnerable system fails to properly handle the input when constructing a ClientHello message for session resumption. As a result, this can lead to a denial of service by crashing the client and potentially allowing the execution of arbitrary code.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.