CVE Database
/

CVE-2015-1182

Back to search

CVE-2015-1182

Published: Jan 27, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2015-0991
vendor-advisory
x_refsource_FEDORA
62270
third-party-advisory
x_refsource_SECUNIA
FEDORA-2015-1045
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2015:0186
vendor-advisory
x_refsource_SUSE
GLSA-201801-15
vendor-advisory
x_refsource_GENTOO
62610
third-party-advisory
x_refsource_SECUNIA
DSA-3136
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now