VYPR

rpm package

opensuse/mbedtls-2&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2025-27810MedMar 25, 2025
    affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1

    Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.

  • CVE-2025-27809MedMar 25, 2025
    affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1

    Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.

  • CVE-2024-45157MedSep 5, 2024
    affected < 2.28.10-bp160.1.1fixed 2.28.10-bp160.1.1

    An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PS