CVE-2018-0488
13.02.2018, 15:29
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 1.3.0 ≤ 𝑥 < 1.3.22 |
arm | mbed_tls | 2.1.0 ≤ 𝑥 < 2.1.10 |
arm | mbed_tls | 2.2.0 ≤ 𝑥 < 2.7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References