Heap-based Buffer Overflow in ARM mbed TLS by PolarSSL
CVE-2015-8036
Currently unrated
Summary
A heap-based buffer overflow vulnerability exists in ARM mbed TLS (formerly PolarSSL) versions prior to 1.3.14 and 2.1.2. This flaw can be exploited by remote SSL servers that send a specially crafted long session ticket name in the session ticket extension, at which point the vulnerable system fails to properly handle the input when constructing a ClientHello message for session resumption. As a result, this can lead to a denial of service by crashing the client and potentially allowing the execution of arbitrary code.
References
Timeline
Vulnerability published
Vulnerability Reserved