CVE Database
/

CVE-2015-5291

Back to search

CVE-2015-5291

Published: Nov 2, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a ClientHello message. NOTE: this identifier has been SPLIT per ADT3 due to different affected version ranges. See CVE-2015-8036 for the session ticket issue that was introduced in 1.3.0.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3468
vendor-advisory
x_refsource_DEBIAN
FEDORA-2015-30a417bea9
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-e22bb33731
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-7f939b3af5
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2015:2257
vendor-advisory
x_refsource_SUSE
GLSA-201706-18
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2015:2371
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now