ARM mbed TLS Heap Buffer Overflow Vulnerability (CVE-2015-8036)
ARM mbed TLS Heap Buffer Overflow Vulnerability (CVE-2015-8036)
Release date:
Updated on:
Affected Systems:
ARM mbed TLS 2. x-2.1.2
ARM mbed TLS 1.3.x-1.3.14
Description:
CVE (CAN) ID: CVE-2015-8036
PolarSSL (mbed TLS) is a dual-Authorization Implementation of SSL, TLS Protocol, its encryption algorithm, and supported algorithms.
ARM mbed TLS 1.3.x-1.3.14, 2. A heap buffer overflow vulnerability exists in the x-2.1.2 version. Attackers can extend the long session ticket name through the session ticket. When a ClientHello message is created, the remote SSL server will reject the service and the client will crash, arbitrary Code may be executed.
<* Source: Guido Vranken
*>
Suggestion:
Vendor patch:
PolarSSL
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2015-01
This article permanently updates the link address: