CVE-2018-0487
13.02.2018, 15:29
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 1.3.8 ≤ 𝑥 < 1.3.22 |
arm | mbed_tls | 2.1.0 ≤ 𝑥 < 2.1.10 |
arm | mbed_tls | 2.2.0 ≤ 𝑥 < 2.7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References