CVE-2017-18187: Integer Overflow
Published Feb 14, 2018
·Updated
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the sslparseclientpskidentity() function in library/sslsrv.c.
Affected Software
4 affected componentsFixes available
Arm mbed TLS<2.7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/mbedtls
2.16.9-0.12.16.9-0.1+deb11u32.28.3-13.6.5-0.1~deb13u13.6.5-0.1
Remediation
Event History
Feb 14, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:14 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:15 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-18187?
CVE-2017-18187 is a vulnerability in ARM mbed TLS before 2.7.0 that allows a bounds-check bypass through an integer overflow in PSK identity parsing.
2
What is the severity of CVE-2017-18187?
CVE-2017-18187 has a severity level of 9.8, which is considered critical.
3
How does CVE-2017-18187 impact ARM mbed TLS?
CVE-2017-18187 affects ARM mbed TLS versions before 2.7.0.
4
How can I fix CVE-2017-18187?
To fix CVE-2017-18187, you should upgrade to ARM mbed TLS version 2.7.0 or later.
5
Where can I find more information about CVE-2017-18187?
You can find more information about CVE-2017-18187 on the SecurityFocus website and the ARM mbed TLS GitHub repository.