~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2018-9989

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2018-9989
2
 
PublicDate: 2018-04-10
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9989
5
 
 https://github.com/ARMmbed/mbedtls/commit/5224a7544c95552553e2e6be0b4a789956a6464e
6
 
 https://github.com/ARMmbed/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd5629e
7
 
 https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-released
8
 
Description:
9
 
 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer
10
 
 over-read in ssl_parse_server_psk_hint() that could cause a crash on
11
 
 invalid input.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
Priority: low
16
 
Discovered-by:
17
 
Assigned-to:
18
 
 
19
 
 
20
 
Patches_mbedtls:
21
 
upstream_mbedtls: released (2.8.0-1)
22
 
precise/esm_mbedtls: DNE
23
 
trusty_mbedtls: DNE
24
 
xenial_mbedtls: needs-triage
25
 
artful_mbedtls: needs-triage
26
 
bionic_mbedtls: needs-triage
27
 
devel_mbedtls: needs-triage
28
 
 
29
 
Patches_polarssl:
30
 
upstream_polarssl: needs-triage
31
 
precise/esm_polarssl: DNE
32
 
trusty_polarssl: needs-triage
33
 
xenial_polarssl: DNE
34
 
artful_polarssl: DNE
35
 
bionic_polarssl: DNE
36
 
devel_polarssl: DNE