Search CVE reports


Toggle filters

1 – 10 of 27 results


CVE-2021-24119

Low priority
Needs evaluation

In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Needs evaluation Needs evaluation Needs evaluation Needs evaluation
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-9989

Low priority
Vulnerable

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Not affected
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-9988

Low priority
Vulnerable

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Not affected
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-19608

Medium priority
Needs evaluation

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Needs evaluation
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0498

Medium priority

Some fixes available 1 of 2

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Vulnerable
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0497

Medium priority

Some fixes available 1 of 2

ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Vulnerable
polarssl Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-0488

High priority

Some fixes available 1 of 2

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected
polarssl Not in release
Show less packages

CVE-2018-0487

High priority

Some fixes available 1 of 2

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected
polarssl Not in release
Show less packages

CVE-2017-2784

Medium priority
Fixed

An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed...

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected
polarssl Not in release
Show less packages

CVE-2017-18187

Medium priority

Some fixes available 1 of 2

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

2 affected packages

mbedtls, polarssl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected
polarssl Not in release
Show less packages