CyberSec.Space Logo
Back to CVE Browser

CVE-2018-0487

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1200%
EPSS Percentile21.83th
PublishedFeb 13, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.

Affected Platforms (CPE)

πŸ“¦
Arm

Mbed Tls

>= 1.3.8 and < 1.3.22
πŸ“¦
Arm

Mbed Tls

>= 2.1.0 and < 2.1.10
πŸ“¦
Arm

Mbed Tls

>= 2.2.0 and < 2.7.0
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0

References & Advisories

Related Vulnerabilities