Mbed-TLS.mbedtls is vulnerable to Buffer Underflow
35
Low Risk
The helper x509_inet_pton_ipv6(), used when parsing IPv6 addresses in X.509 name handling, mishandles buffer bounds. Parsing crafted IPv6 address input drives an out-of-bounds access around a stack buffer. This can corrupt memory and crash the process. The fix corrects the bounds handling in the IPv6 parsing routine.
You are affected if you are using a version that falls within the vulnerable range and your application parses X.509 data containing untrusted IPv6 address strings.
Mbed-TLS.mbedtls is vulnerable to Buffer Underflow in versions 3.5.0 - 3.6.5 and 4.0.0 - 4.0.0.
Upgrade the Mbed-TLS.mbedtls library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant