[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3967-1 mbedtls -- mbedtls

ID: oval:org.secpod.oval:def:603092Date: (C)2017-09-11   (M)2023-04-19
Class: PATCHFamily: unix




An authentication bypass vulnerability was discovered in mbed TLS, a lightweight crypto and SSL/TLS library, when the authentication mode is configured as "optional". A remote attacker can take advantage of this flaw to mount a man-in-the-middle attack and impersonate an intended peer via an X.509 certificate chain with many intermediates.

Platform:
Debian 9.x
Product:
libmbedtls-doc
libmbedtls-dev
libmbedtls10
libmbedcrypto0
libmbedx509-0
Reference:
DSA-3967-1
CVE-2017-14032
CVE    1
CVE-2017-14032
CPE    2
cpe:/a:mbed:libmbedtls-dev
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies