Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-36425

Опубликовано: 19 июл. 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mbedtlsfixed2.16.9-0.1package
mbedtlsno-dsastretchpackage

Примечания

  • https://github.com/ARMmbed/mbedtls/issues/3340

  • https://github.com/ARMmbed/mbedtls/pull/3433

EPSS

Процентиль: 74%
0.00809
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

CVSS3: 5.3
nvd
больше 4 лет назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

msrc
5 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

CVSS3: 5.3
github
больше 3 лет назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость реализации протоколов TLS и SSL Mbed TLS, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 74%
0.00809
Низкий