CVE-2015-8036Improper Restriction of Operations within the Bounds of a Memory Buffer in ARM Mbed TLS

Severity
6.8MEDIUMNVD
EPSS
1.4%
top 19.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 14

Description

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session. NOTE: this identifier was SPLIT from CVE-2015-5291 per ADT3 due to different affected version ranges.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDarm/mbed_tls1.3.01.3.14+1
NVDpolarssl/polarssl1.0.01.2.17+1
Ubuntumbed/mbedtls< 2.2.1-2
NVDopensuse/leap42.1

Also affects: Debian Linux 7.0, 8.0, Fedora 21, 22, 23

🔴Vulnerability Details

6
GHSA
GHSA-hhcq-g9mx-qpfg: Heap-based buffer overflow in PolarSSL 12022-05-14
GHSA
GHSA-h6fm-cj44-vv3x: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 12022-05-14
CVEList
CVE-2015-5291: Heap-based buffer overflow in PolarSSL 12015-11-02
OSV
CVE-2015-8036: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 12015-11-02
CVEList
CVE-2015-8036: Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 12015-11-02

📋Vendor Advisories

2
Debian
CVE-2015-5291: mbedtls - Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (forme...2015
Debian
CVE-2015-8036: mbedtls - Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3....2015

💬Community

4
Bugzilla
CVE-2015-5291 CVE-2015-8036 polarssl: mbedtls: crash or remote code execution on clients using session tickets or SNI2015-10-09
Bugzilla
CVE-2015-5291 CVE-2015-8036 polarssl: mbedtls: crash or remote code execution on clients using session tickets or SNI [fedora-all]2015-10-09
Bugzilla
CVE-2015-5291 CVE-2015-8036 polarssl: mbedtls: crash or remote code execution on clients using session tickets or SNI [fedora-all]2015-10-09
Bugzilla
CVE-2015-5291 CVE-2015-8036 polarssl: mbedtls: crash or remote code execution on clients using session tickets or SNI [epel-all]2015-10-09
CVE-2015-8036 — ARM Mbed TLS vulnerability | cvebase