Bug ID | 989694 |
---|---|
Summary | VUL-0: polarssl CVE-2015-8036 |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | 13.2 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Normal |
Priority | P5 - None |
Component | Basesystem |
Assignee | mpluskal@suse.com |
Reporter | mpluskal@suse.com |
QA Contact | qa-bugs@suse.de |
Found By | --- |
Blocker | --- |
polarssl-1.3.9 from openSUSE-13.2 seems to be vulnerable to following issue: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session. NOTE: this identifier was SPLIT from CVE-2015-5291 per ADT3 due to different affected version ranges.