CVE-2020-36476
23.08.2021, 02:15
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.Enginsight
Vendor | Product | Version |
---|---|---|
arm | mbed_tls | 𝑥 < 2.7.17 |
arm | mbed_tls | 2.8.0 ≤ 𝑥 < 2.16.8 |
arm | mbed_tls | 2.17.0 ≤ 𝑥 < 2.24.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References