The remote code execution capability exists in some versions of the open-source PolarSSL SSL library and is due to a vulnerability that can be caused during a certificate.
The bug is triggered after the certificate is verified
This vulnerability, now identified as CVE-2015-1182, was discovered internally by PolarSSL and was also reported by an external company, Certified Secure.
"When an X.509 certificate is parsed by the PolarSSL, the vulnerability allows remote code execution and a denial of service. The most common scenario is a server using the PolarSSL to verify client certificates," Certified Secure in a blog post.
The risk to the victim if an attacker manages to exploit the vulnerability is at least a denial-of-service. The biggest threat is remote execution of arbitrary code on the user's system.
PolarSSL library that allows developers to include encryption and SSL/TLS functionality in their products. It is used in a number of important projects, such as cURL, OpenVPN, PowerDNS , and mobile devices.
To address the problem, the developers offer two solutions. The first solution consists of the user adding a patch to the original source code of the products that integrate PolarSSL. The second is for cases where there is a time crunch and consists of the user waiting until a new version is released.
Product versions from version 1.0 through 1.3.9, along with the 1.2.12 build, are affected by this security vulnerability.
An unofficial patch is also available, for version 1.3.9 of the library, and is provided by Certified Secure.

