A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input passwords length is 0.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Mbed_tls | Arm | * | 3.0.0 (including) | 
| Mbedtls | Ubuntu | bionic | * | 
| Mbedtls | Ubuntu | esm-apps/bionic | * | 
| Mbedtls | Ubuntu | esm-apps/focal | * | 
| Mbedtls | Ubuntu | esm-apps/xenial | * | 
| Mbedtls | Ubuntu | focal | * | 
| Mbedtls | Ubuntu | impish | * | 
| Mbedtls | Ubuntu | kinetic | * | 
| Mbedtls | Ubuntu | lunar | * | 
| Mbedtls | Ubuntu | mantic | * | 
| Mbedtls | Ubuntu | oracular | * | 
| Mbedtls | Ubuntu | trusty | * | 
| Mbedtls | Ubuntu | upstream | * | 
| Mbedtls | Ubuntu | xenial | * |