PolarSSL Heap Buffer Overflow Vulnerability (CVE-2015-5291)
PolarSSL Heap Buffer Overflow Vulnerability (CVE-2015-5291)
Release date:
Updated on:
Affected Systems:
PolarSSL 1. x-1.2.17
Description:
CVE (CAN) ID: CVE-2015-5291
PolarSSL (mbed TLS) is a dual-Authorization Implementation of SSL, TLS Protocol, its encryption algorithm, and supported algorithms.
PolarSSL 1. x-1.2.17, ARM mbed TLS 1.3.x-1.3.14, 2. the x-2.1.2 version has a heap buffer overflow vulnerability that allows attackers to send long hostnames to SNI extensions. When a ClientHello message is created with an error, the remote SSL server rejects the service and the client crashes, arbitrary Code may be executed.
<* Source: Guido Vranken
*>
Suggestion:
Vendor patch:
PolarSSL
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2015-01
PolarSSL details: click here
PolarSSL: click here
This article permanently updates the link address: