Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14032

Опубликовано: 30 авг. 2017
Источник: debian

Описание

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.6.0-1package
polarsslremovedpackage
polarsslnot-affectedjessiepackage
polarsslnot-affectedwheezypackage

Примечания

  • Affected versions: all from version 1.3.10 up and including 2.1 and later releases

  • https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02

  • https://github.com/ARMmbed/mbedtls/commit/31458a18788b0cf0b722acda9bb2f2fe13a3fb32

  • https://github.com/ARMmbed/mbedtls/commit/d15795acd5074e0b44e71f7ede8bdfe1b48591fc

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

CVSS3: 8.1
nvd
больше 8 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

CVSS3: 8.1
github
больше 3 лет назад

ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.