CVE Published: 13/02/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: debian |
Vendor: n/a |
Product: ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 Status : PUBLISHED
CVE-2018-0488 Description
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.