Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-27809

Опубликовано: 25 мар. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

РелизСтатусПримечание
devel

not-affected

3.6.5-0.1ubuntu2
esm-apps-legacy/xenial

ignored

changes too intrusive
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

ignored

changes too intrusive
esm-apps/resolute

not-affected

3.6.5-0.1ubuntu2
esm-apps/xenial

ignored

end of ESM support, was ignored [changes too intrusive]
focal

ignored

end of standard support, was needs-triage
jammy

ignored

changes too intrusive

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

msrc
12 месяцев назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

CVSS3: 5.4
debian
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, acce ...

CVSS3: 5.4
github
больше 1 года назад

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

CVSS3: 5.4
fstec
больше 1 года назад

Уязвимость функции mbedtls_ssl_set_hostname программного обеспечения Mbed TLS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.4 Medium

CVSS3