Critical severity9.8NVD Advisory· Published Feb 14, 2018· Updated Jun 17, 2026
CVE-2017-18187
CVE-2017-18187
Description
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5Patches
Vulnerability mechanics
References
7- github.com/ARMmbed/mbedtls/commit/83c9f495ffe70c7dd280b41fdfd4881485a3bc28nvdPatchThird Party Advisory
- www.securityfocus.com/bid/103055nvdThird Party AdvisoryVDB Entry
- github.com/ARMmbed/mbedtls/blob/master/ChangeLognvdThird Party Advisory
- security.gentoo.org/glsa/201804-19nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4138nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4147nvdThird Party Advisory
- usn.ubuntu.com/4267-1/nvd
News mentions
0No linked articles in our index yet.