CyberSec.Space Logo
CVEブラウザに戻る

CVE-2017-18187

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0140%
EPSS Percentile9.79th
Published2018年2月14日
Last Modified2024年11月21日

Vulnerability Description

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

Affected Platforms (CPE)

📦
Arm

Mbed Tls

< 2.7.0
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0

References & Advisories

関連する脆弱性情報