Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18187

Опубликовано: 14 фев. 2018
Источник: debian
EPSS Низкий

Описание

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.7.0-2package
polarsslremovedpackage
polarsslnot-affectedwheezypackage

Примечания

  • https://github.com/ARMmbed/mbedtls/commit/83c9f495ffe70c7dd280b41fdfd4881485a3bc28

EPSS

Процентиль: 61%
0.00415
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

CVSS3: 9.8
nvd
почти 8 лет назад

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

CVSS3: 9.8
github
больше 3 лет назад

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

EPSS

Процентиль: 61%
0.00415
Низкий