CVE-2023-43615: Buffer Overflow
Published Oct 7, 2023
·Updated
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
Affected Software
8 affected componentsFixes available
Arm mbed TLS>=2.0.0<2.28.5
Arm mbed TLS>=3.0.0<3.5.0
Fedoraproject Fedora=38
Microsoft cbl2 hvloader 1.0.1-5
Microsoft cbl2 hvloader 1.0.1-5
TrustedFirmware Mbed Tls>=3.0.0<3.5.0
Fedoraproject Fedora=37
Fedoraproject Fedora=39
Event History
Oct 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 28, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-43615?
CVE-2023-43615 is a vulnerability in Mbed TLS versions 2.x before 2.28.5 and 3.x before 3.5.0 that causes a buffer overflow.
2
How severe is CVE-2023-43615?
CVE-2023-43615 has a severity score of 7.5 out of 10, indicating a high severity.
3
Which software versions are affected by CVE-2023-43615?
Mbed TLS versions 2.x before 2.28.5 and 3.x before 3.5.0 are affected by CVE-2023-43615.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-43615?
CVE-2023-43615 is associated with CWE-119 and CWE-120.
5
How can I fix CVE-2023-43615?
To fix CVE-2023-43615, update Mbed TLS to version 2.28.5 or later for versions 2.x, and to version 3.5.0 or later for versions 3.x.