PT-2015-7712 · Arm+1 · Arm Mbed Tls+1
Publicado
2015-11-02
·
Atualizado
2026-06-05
·
CVE-2015-8036
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ARM mbed TLS versions 1.3.x through 1.3.13
ARM mbed TLS versions 2.x through 2.1.1
Description
The issue is related to a heap-based buffer overflow in ARM mbed TLS, which can be triggered by remote SSL servers. This occurs when a long session ticket name is sent to the session ticket extension, and it is not properly handled when creating a ClientHello message to resume a session. This can cause a denial of service, resulting in the client crashing, and potentially allow for the execution of arbitrary code.
Recommendations
For ARM mbed TLS versions 1.3.x through 1.3.13, update to version 1.3.14 or later.
For ARM mbed TLS versions 2.x through 2.1.1, update to version 2.1.2 or later.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Arm Mbed Tls