CVE-2015-1182
Gentoo Linux Security Advisory 201801-15
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.
La función asn1_get_sequence_of en library/asn1parse.c en PolarSSL 1.0 hasta 1.2.12 y 1.3.x hasta 1.3.9 no inicializa correctamente un puntero en la lista vinculada asn1_sequence, lo que permite a atacantes remotos causar una denegación de servicio (caída) o posiblemente ejecutar código arbitrario a través de una secuencias ASN.1 manipulada en un certificado.
Multiple vulnerabilities have been found in PolarSSL, the worst of which may allow remote attackers to execute arbitrary code. Versions less than 1.3.9-r1 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-17 CVE Reserved
- 2015-01-27 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/62270 | Third Party Advisory | |
http://secunia.com/advisories/62610 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.2 Search vendor "Opensuse" for product "Opensuse" and version "13.2" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.0.0 Search vendor "Polarssl" for product "Polarssl" and version "1.0.0" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.0 Search vendor "Polarssl" for product "Polarssl" and version "1.1.0" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.0 Search vendor "Polarssl" for product "Polarssl" and version "1.1.0" | rc0 |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.0 Search vendor "Polarssl" for product "Polarssl" and version "1.1.0" | rc1 |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.1 Search vendor "Polarssl" for product "Polarssl" and version "1.1.1" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.2 Search vendor "Polarssl" for product "Polarssl" and version "1.1.2" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.3 Search vendor "Polarssl" for product "Polarssl" and version "1.1.3" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.4 Search vendor "Polarssl" for product "Polarssl" and version "1.1.4" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.5 Search vendor "Polarssl" for product "Polarssl" and version "1.1.5" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.6 Search vendor "Polarssl" for product "Polarssl" and version "1.1.6" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.7 Search vendor "Polarssl" for product "Polarssl" and version "1.1.7" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.1.8 Search vendor "Polarssl" for product "Polarssl" and version "1.1.8" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.0 Search vendor "Polarssl" for product "Polarssl" and version "1.2.0" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.1 Search vendor "Polarssl" for product "Polarssl" and version "1.2.1" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.2 Search vendor "Polarssl" for product "Polarssl" and version "1.2.2" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.3 Search vendor "Polarssl" for product "Polarssl" and version "1.2.3" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.4 Search vendor "Polarssl" for product "Polarssl" and version "1.2.4" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.5 Search vendor "Polarssl" for product "Polarssl" and version "1.2.5" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.6 Search vendor "Polarssl" for product "Polarssl" and version "1.2.6" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.7 Search vendor "Polarssl" for product "Polarssl" and version "1.2.7" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.8 Search vendor "Polarssl" for product "Polarssl" and version "1.2.8" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.9 Search vendor "Polarssl" for product "Polarssl" and version "1.2.9" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.10 Search vendor "Polarssl" for product "Polarssl" and version "1.2.10" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.11 Search vendor "Polarssl" for product "Polarssl" and version "1.2.11" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.2.12 Search vendor "Polarssl" for product "Polarssl" and version "1.2.12" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.0 Search vendor "Polarssl" for product "Polarssl" and version "1.3.0" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.0 Search vendor "Polarssl" for product "Polarssl" and version "1.3.0" | alpha1 |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.0 Search vendor "Polarssl" for product "Polarssl" and version "1.3.0" | rc0 |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.1 Search vendor "Polarssl" for product "Polarssl" and version "1.3.1" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.2 Search vendor "Polarssl" for product "Polarssl" and version "1.3.2" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.3 Search vendor "Polarssl" for product "Polarssl" and version "1.3.3" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.4 Search vendor "Polarssl" for product "Polarssl" and version "1.3.4" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.5 Search vendor "Polarssl" for product "Polarssl" and version "1.3.5" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.6 Search vendor "Polarssl" for product "Polarssl" and version "1.3.6" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.7 Search vendor "Polarssl" for product "Polarssl" and version "1.3.7" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.8 Search vendor "Polarssl" for product "Polarssl" and version "1.3.8" | - |
Affected
| ||||||
Polarssl Search vendor "Polarssl" | Polarssl Search vendor "Polarssl" for product "Polarssl" | 1.3.9 Search vendor "Polarssl" for product "Polarssl" and version "1.3.9" | - |
Affected
|