CVE-2015-1182 describes a denial-of-service or potential arbitrary code execution vulnerability in PolarSSL versions 1.0 through 1.2.12 and 1.3.x through 1.3.9, specifically within the asn1_get_sequence_of function. This flaw, affecting products like openSUSE, stems from improper pointer initialization when processing crafted ASN.1 sequences in certificates. With a CVSS score of 7.5, it is a high-severity vulnerability that can be exploited remotely with low attack complexity, potentially leading to a crash or code execution. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:polarssl:polarssl:1.0.0:*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:polarssl:polarssl:1.1.0:*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:polarssl:polarssl:1.1.0:rc0:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:polarssl:polarssl:1.1.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.