Mbed TLS
0 remedies
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*, +1 more
0 remedies
- < 3.6.4
A heap-based buffer underflow vulnerability has been identified in Mbed TLS versions prior to 3.6.4. This issue arises in the PEM parsing functions, specifically 'mbedtls_pem_read_buffer' and two 'mbedtls_pk_parse' functions, when handling untrusted PEM input.
Exploitation of this vulnerability leads to a heap-based buffer underflow, which can potentially be exploited to cause memory corruption.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.