Vulnerability Description
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | < 2.1.11 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://github.com/ARMmbed/mbedtls/commit/5224a7544c95552553e2e6be0b4a789956a646PatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd562PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00029.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlMailing ListThird Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-releasRelease NotesVendor Advisory
- https://github.com/ARMmbed/mbedtls/commit/5224a7544c95552553e2e6be0b4a789956a646PatchThird Party Advisory
- https://github.com/ARMmbed/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd562PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00029.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00021.htmlMailing ListThird Party Advisory
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.8.0-2.7.2-and-2.1.11-releasRelease NotesVendor Advisory
FAQ
What is CVE-2018-9989?
CVE-2018-9989 is a vulnerability with a CVSS score of 7.5 (HIGH). ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
How severe is CVE-2018-9989?
CVE-2018-9989 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9989?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls, Debian Debian Linux.