Search CVE reports
1 – 10 of 27 results
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and...
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
polarssl | Not in release | Not in release | Not in release | Not in release |
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Not affected | Not affected | Not affected | Not affected |
polarssl | Not in release | Not in release | Not in release | Not in release |
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Not affected | Not affected | Not affected | Not affected |
polarssl | Not in release | Not in release | Not in release | Not in release |
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Not affected | Not affected | Not affected | Needs evaluation |
polarssl | Not in release | Not in release | Not in release | Not in release |
Some fixes available 1 of 2
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Not affected | Not affected | Not affected | Vulnerable |
polarssl | Not in release | Not in release | Not in release | Not in release |
Some fixes available 1 of 2
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of...
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | Not affected | Not affected | Not affected | Vulnerable |
polarssl | Not in release | Not in release | Not in release | Not in release |
Some fixes available 1 of 2
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted...
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | — | — | — | Not affected |
polarssl | — | — | — | Not in release |
Some fixes available 1 of 2
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS...
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | — | — | — | Not affected |
polarssl | — | — | — | Not in release |
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed...
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | — | — | — | Not affected |
polarssl | — | — | — | Not in release |
Some fixes available 1 of 2
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
2 affected packages
mbedtls, polarssl
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mbedtls | — | — | — | Not affected |
polarssl | — | — | — | Not in release |