In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-mbedtlsalpine-linux-upgrade-mbedtls2alpine-linux-upgrade-mbedtls3 | Jul 31, 2018 | Feb 14, 2018 | |
| Debian | debian-upgrade-mbedtls | Mar 17, 2018 | Feb 14, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-libs-mbedtls | Apr 23, 2018 | Feb 14, 2018 | |
| Suse | — | suse-upgrade-libmbedtls9suse-upgrade-mbedtls-devel | Feb 21, 2018 | Feb 14, 2018 |
| Ubuntu | ubuntu-upgrade-libmbedcrypto0ubuntu-upgrade-libmbedtls10ubuntu-upgrade-libmbedx509-0 | Feb 6, 2020 | Feb 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub