PT-2015-5151 · Openssl · Polarssl

Published

2015-01-24

·

Updated

2024-06-15

·

CVE-2015-1182

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PolarSSL versions 1.0 through 1.2.12 PolarSSL versions 1.3.x through 1.3.9
Description The issue is related to the improper initialization of a pointer in the asn1 sequence linked list by the asn1 get sequence of function. This can be exploited by remote attackers using a crafted ASN.1 sequence in a certificate, potentially leading to a denial of service (crash) or possibly the execution of arbitrary code.
Recommendations For PolarSSL versions 1.0 through 1.2.12, update to a version outside of this range to resolve the issue. For PolarSSL versions 1.3.x through 1.3.9, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of the asn1 get sequence of function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-1182
DLA-144-1
DSA-3136-1
MGASA-2015-0055
OPENSUSE-SU-2024:10088-1
OPENSUSE-SU-2024:12903-1

Affected Products

Polarssl