openSUSE-SU-2017:0792-1

    Dashboard / Vulnerabilities / openSUSE-SU-2017:0792-1

    openSUSE-SU-2017:0792-1

    Published: 22 Mar 2017Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for mbedtls

    Details: This update to mbedtls 1.3.19 fixes security issues and bugs. The following vulnerability was fixed: CVE-2017-2784: A remote user could have used a specially crafted certificate to cause mbedtls to free a buffer allocated on the stack when verifying the validity of public key with a secp224k1 curve, which could have allowed remote code execution on some platforms (boo#1029017) The following non-security changes are included: - Add checks to prevent signature forgeries for very large messages while using RSA through the PK module in 64-bit systems. - Fixed potential livelock during the parsing of a CRL in PEM format

    Affected packages

    Package

    Name: mbedtls

    Purl: pkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2012

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.3.19-5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2017:0792-1 | CVE-DB