openSUSE-SU-2017:0792-1
Dashboard / Vulnerabilities / openSUSE-SU-2017:0792-1
openSUSE-SU-2017:0792-1
Summary: Security update for mbedtls
Details: This update to mbedtls 1.3.19 fixes security issues and bugs. The following vulnerability was fixed: CVE-2017-2784: A remote user could have used a specially crafted certificate to cause mbedtls to free a buffer allocated on the stack when verifying the validity of public key with a secp224k1 curve, which could have allowed remote code execution on some platforms (boo#1029017) The following non-security changes are included: - Add checks to prevent signature forgeries for very large messages while using RSA through the PK module in 64-bit systems. - Fixed potential livelock during the parsing of a CRL in PEM format
References: https://lists.opensuse.org/archives/list/[email protected]/thread/FAMN75AB4YE4LABPQEYS2NAM6F32VCFZ/#FAMN75AB4YE4LABPQEYS2NAM6F32VCFZ, https://bugzilla.suse.com/1029017, https://www.suse.com/security/cve/CVE-2017-2784
Affected packages
Package
Name: mbedtls
Purl: pkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
