PT-2015-7712 · Arm+1 · Arm Mbed Tls+1

Publicado

2015-11-02

·

Atualizado

2026-06-05

·

CVE-2015-8036

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ARM mbed TLS versions 1.3.x through 1.3.13 ARM mbed TLS versions 2.x through 2.1.1
Description The issue is related to a heap-based buffer overflow in ARM mbed TLS, which can be triggered by remote SSL servers. This occurs when a long session ticket name is sent to the session ticket extension, and it is not properly handled when creating a ClientHello message to resume a session. This can cause a denial of service, resulting in the client crashing, and potentially allow for the execution of arbitrary code.
Recommendations For ARM mbed TLS versions 1.3.x through 1.3.13, update to version 1.3.14 or later. For ARM mbed TLS versions 2.x through 2.1.1, update to version 2.1.2 or later.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1956
CVE-2015-8036
DSA-3468-1
MGASA-2016-0054

Produtos afetados

Alt Linux
Arm Mbed Tls