Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9989

Опубликовано: 10 апр. 2018
Источник: debian
EPSS Низкий

Описание

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.8.0-1package
polarsslremovedpackage
polarsslno-dsawheezypackage

Примечания

  • https://github.com/ARMmbed/mbedtls/commit/5224a7544c95552553e2e6be0b4a789956a6464e

  • https://github.com/ARMmbed/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd5629e

  • https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-released

EPSS

Процентиль: 60%
0.00403
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

CVSS3: 7.5
nvd
почти 8 лет назад

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

CVSS3: 7.5
github
больше 3 лет назад

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

EPSS

Процентиль: 60%
0.00403
Низкий