Back to search
CVE-2015-1182
Published: Jan 27, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2015-0991
vendor-advisory
x_refsource_FEDORA
62270
third-party-advisory
x_refsource_SECUNIA
FEDORA-2015-1045
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2015:0186
vendor-advisory
x_refsource_SUSE
GLSA-201801-15
vendor-advisory
x_refsource_GENTOO
62610
third-party-advisory
x_refsource_SECUNIA
DSA-3136
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now