Security Advisory

CVE-2018-0487

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-02-13 15:00:00
Last updated 2024-08-05 03:28:11
Assigner debian
CVSS score not scored
State PUBLISHED

Description

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.