PT-2015-7712 · Arm+1 · Arm Mbed Tls+1

Published

2015-11-02

·

Updated

2026-06-05

·

CVE-2015-8036

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ARM mbed TLS versions 1.3.x through 1.3.13 ARM mbed TLS versions 2.x through 2.1.1
Description The issue is related to a heap-based buffer overflow in ARM mbed TLS, which can be triggered by remote SSL servers. This occurs when a long session ticket name is sent to the session ticket extension, and it is not properly handled when creating a ClientHello message to resume a session. This can cause a denial of service, resulting in the client crashing, and potentially allow for the execution of arbitrary code.
Recommendations For ARM mbed TLS versions 1.3.x through 1.3.13, update to version 1.3.14 or later. For ARM mbed TLS versions 2.x through 2.1.1, update to version 2.1.2 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1956
CVE-2015-8036
DSA-3468-1
MGASA-2016-0054

Affected Products

Alt Linux
Arm Mbed Tls