Vulnerability Description
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | < 2.1.11 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://github.com/ARMmbed/mbedtls/commit/027f84c69f4ef30c0693832a6c396ef19e563cPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/a1098f81c252b317ad34ea978aea2bc47760b2PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00029.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlMailing ListThird Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-releasRelease NotesVendor Advisory
- https://github.com/ARMmbed/mbedtls/commit/027f84c69f4ef30c0693832a6c396ef19e563cPatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/a1098f81c252b317ad34ea978aea2bc47760b2PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00029.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlMailing ListThird Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-releasRelease NotesVendor Advisory
FAQ
What is CVE-2018-9988?
CVE-2018-9988 is a vulnerability with a CVSS score of 7.5 (HIGH). ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
How severe is CVE-2018-9988?
CVE-2018-9988 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9988?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls, Debian Debian Linux.