rpm package
opensuse/mbedtls-2&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-27810 | Med | 5.4 | < 2.28.10-bp160.1.1 | 2.28.10-bp160.1.1 | Mar 25, 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays. | |
| CVE-2025-27809 | Med | 5.4 | < 2.28.10-bp160.1.1 | 2.28.10-bp160.1.1 | Mar 25, 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname. | |
| CVE-2024-45157 | Med | 5.1 | < 2.28.10-bp160.1.1 | 2.28.10-bp160.1.1 | Sep 5, 2024 | An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PS |
- affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
- affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
- affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PS