Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-0488

Опубликовано: 13 фев. 2018
Источник: debian
EPSS Низкий

Описание

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.7.0-2package
polarsslremovedpackage
polarsslnot-affectedwheezypackage

Примечания

  • https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-01

  • https://github.com/ARMmbed/mbedtls/commit/992b6872f3ca717282ae367749a47f006d337a87

  • https://github.com/ARMmbed/mbedtls/commit/464147cadc694379b7717afb7b517fe05cdb323f

EPSS

Процентиль: 92%
0.04793
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.

CVSS3: 9.8
nvd
больше 8 лет назад

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.

CVSS3: 9.8
github
больше 4 лет назад

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.

EPSS

Процентиль: 92%
0.04793
Низкий