A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input passwords length is 0.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mbed_tls | Arm | * | 3.0.0 (including) |
Mbedtls | Ubuntu | bionic | * |
Mbedtls | Ubuntu | impish | * |
Mbedtls | Ubuntu | kinetic | * |
Mbedtls | Ubuntu | lunar | * |
Mbedtls | Ubuntu | mantic | * |
Mbedtls | Ubuntu | trusty | * |
Mbedtls | Ubuntu | xenial | * |