
We found results for “”
CVE-2024-23775
Good to know:

Date: January 30, 2024
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
Language: C
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Integer Overflow or Wraparound
CWE-190Top Fix

Upgrade Version
Upgrade to version hactool-sys - no_fix;mbedtls-sys-auto - 2.28.7;mbedtls-sys-auto - no_fix;librist-sys - no_fix;openthread-sys - 0.1.3;openthread-sys - no_fix;tlsimple - no_fix;drogue-tls-sys - no_fix;psa-crypto-sys - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |