The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:POpensuse
OSOpensuse13.2Polarssl
APPPolarssl1.0.01.1.01.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.2.01.2.11.2.101.2.111.2.12+ 18 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDoS
References
Related vulnerabilities
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-4117CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — RCE umożliwiający wykonanie dowolnego kodu
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2015-5119CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — use-after-free w klasie ByteArray umożliwia RCE