Bug 913903 (CVE-2015-1182) - VUL-0: CVE-2015-1182 polarssl: remote attack using crafted certificates
Summary: VUL-0: CVE-2015-1182 polarssl: remote attack using crafted certificates
Status: RESOLVED FIXED
Alias: CVE-2015-1182
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P5 - None : Major
Target Milestone: ---
Assignee: Mariusz Fik
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/112811/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-20 15:15 UTC by Victor Pereira
Modified: 2015-03-27 14:44 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-20 15:15:31 UTC
rh#1184028

The following flaw was found in PolarSSL:

During the parsing of a ASN.1 sequence, a pointer in the linked list of asn1_sequence is not initialized by asn1_get_sequence_of(). In case an error occurs during parsing of the list, a situation is created where the uninitialized pointer is passed to polarssl_free().

This sequence can be triggered when a PolarSSL entity is parsing a certificate. So practically this means clients when receiving a certificate from the server or servers in case they are actively asking for a client certificate.

Depending on the attackers knowledge of the system under attack, this results at the lowest into a Denial of Service, and at the most a possible Remote Code Execution.

The patch for this issue is provided in the PolarSSL Security Advisory 2014-04 referenced below.

References:
https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-04
https://bugzilla.redhat.com/show_bug.cgi?id=1184028
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1182
Comment 1 Bernhard Wiedemann 2015-01-20 20:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (913903) was mentioned in
https://build.opensuse.org/request/show/282143 Factory / polarssl
https://build.opensuse.org/request/show/282145 13.2 / polarssl
Comment 2 Swamp Workflow Management 2015-02-02 09:04:56 UTC
openSUSE-SU-2015:0186-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 913903
CVE References: CVE-2015-1182
Sources used:
openSUSE 13.2 (src):    polarssl-1.3.9-8.1
Comment 3 Marcus Meissner 2015-03-27 14:44:59 UTC
resolved apparently