Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-48965

Опубликовано: 20 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4

Описание

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

РелизСтатусПримечание
devel

not-affected

3.6.5-0.1ubuntu2
esm-apps-legacy/xenial

needed

esm-apps/bionic

released

2.8.0-1ubuntu0.1~esm1
esm-apps/focal

released

2.16.4-1ubuntu2+esm1
esm-apps/jammy

released

2.28.0-1ubuntu0.1~esm1
esm-apps/noble

released

2.28.8-1ubuntu0.1~esm1
esm-apps/resolute

not-affected

3.6.5-0.1ubuntu2
esm-apps/xenial

ignored

end of ESM support, was needed
jammy

needed

noble

needed

Показывать по

EPSS

Процентиль: 40%
0.00484
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
nvd
около 1 года назад

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

CVSS3: 4
debian
около 1 года назад

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_a ...

CVSS3: 4
github
около 1 года назад

Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero.

CVSS3: 4
fstec
около 1 года назад

Уязвимость функции mbedtls_asn1_store_named_data программного обеспечения Mbed TLS, позволяющая нарушителю выполнить произвольный код

suse-cvrf
3 месяца назад

Security update for mbedtls

EPSS

Процентиль: 40%
0.00484
Низкий

4 Medium

CVSS3