PT-2015-7712 · Arm+1 · Arm Mbed Tls+1
Published
2015-11-02
·
Updated
2026-06-05
·
CVE-2015-8036
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ARM mbed TLS versions 1.3.x through 1.3.13
ARM mbed TLS versions 2.x through 2.1.1
Description
The issue is related to a heap-based buffer overflow in ARM mbed TLS, which can be triggered by remote SSL servers. This occurs when a long session ticket name is sent to the session ticket extension, and it is not properly handled when creating a ClientHello message to resume a session. This can cause a denial of service, resulting in the client crashing, and potentially allow for the execution of arbitrary code.
Recommendations
For ARM mbed TLS versions 1.3.x through 1.3.13, update to version 1.3.14 or later.
For ARM mbed TLS versions 2.x through 2.1.1, update to version 2.1.2 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Arm Mbed Tls