CVE Feed

    Dashboard / CVE / CVE-2015-5291

    CVE-2015-5291

    Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a ClientHello message. NOTE: this identifier has been SPLIT per ADT3 due to different affected version ranges. See CVE-2015-8036 for the session ticket issue that was introduced in 1.3.0.

    Published:Nov 2, 2015
    Last Modified:Jun 5, 2026
    EPS:Nov 2, 2015
    EPSS Score:0.02049
    CVSS Score:6.8

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Opensuse
    Product
    Opensuse
    Vendor
    Polarssl
    Product
    Polarssl
    Vendor
    Trustedfirmware
    Product
    Mbed Tls

    Exploits

    No exploit reference

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High