Information on source package mbedtls

Available versions

ReleaseVersion
stretch2.4.2-1+deb9u3
buster2.16.0-1
bullseye2.16.9-0.1
sid2.16.9-0.1

Open issues

BugstretchbusterbullseyesidDescription
CVE-2020-16150vulnerable (no DSA)vulnerable (no DSA)fixedfixedA Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/s ...
CVE-2020-10941vulnerable (no DSA)vulnerable (no DSA)fixedfixedArm Mbed TLS before 2.6.15 allows attackers to obtain sensitive inform ...
CVE-2020-10932vulnerable (no DSA)vulnerable (no DSA)fixedfixedAn issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before ...
CVE-2019-18222vulnerable (no DSA)vulnerable (no DSA)fixedfixedThe ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 a ...
CVE-2019-16910vulnerable (no DSA)vulnerable (no DSA)fixedfixedArm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when dete ...
CVE-2018-9989vulnerable (no DSA)fixedfixedfixedARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffe ...
CVE-2018-9988vulnerable (no DSA)fixedfixedfixedARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffe ...
CVE-2018-19608vulnerable (no DSA)fixedfixedfixedArm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a l ...

Open unimportant issues

BugstretchbusterbullseyesidDescription
CVE-2018-1000520vulnerablevulnerablevulnerablevulnerableARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows In ...

Resolved issues

BugDescription
CVE-2018-0498ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows loc ...
CVE-2018-0497ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows rem ...
CVE-2018-0488ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the ...
CVE-2018-0487ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows rem ...
CVE-2017-2784An exploitable free of a stack pointer vulnerability exists in the x50 ...
CVE-2017-18187In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through a ...
CVE-2017-14032ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentic ...
CVE-2015-8036Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x b ...
CVE-2015-5291Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed ...

Security announcements

DSA / DLADescription
DSA-4296-1mbedtls - security update
DSA-4138-1mbedtls - security update
DSA-3967-1mbedtls - security update

Search for package or bug name: Reporting problems