Lucene search

K
archlinuxArch LinuxASA-201501-13
HistoryJan 20, 2015 - 12:00 a.m.

polarssl: remote code execution

2015-01-2000:00:00
Arch Linux
lists.archlinux.org
24

EPSS

0.042

Percentile

92.3%

During the parsing of a ASN.1 sequence, a pointer in the linked list of
asn1_sequence is not initialized by asn1_get_sequence_of(). In case an
error occurs during parsing of the list, a situation is created where
the uninitialized pointer is passed to polarssl_free().

This sequence can be triggered when a PolarSSL entity is parsing a
certificate. So practically this means clients when receiving a
certificate from the server or servers in case they are actively asking
for a client certificate.

OSVersionArchitecturePackageVersionFilename
anyanyanypolarssl< 1.3.9-2UNKNOWN