Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 08:58
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GP5UU7Z6LJNBLBT4SC5WWS2HDNMTFZH5/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IIBPEYSVRK4IFLBSYJAWKH33YBNH5HR2/ - | |
| References | () https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/ - Vendor Advisory | 
22 Feb 2024, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
17 Feb 2024, 02:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
09 Feb 2024, 01:00
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.5 | 
| First Time | Arm Arm mbed Tls | |
| CPE | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | |
| CWE | CWE-190 | |
| References | () https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-2/ - Vendor Advisory | 
31 Jan 2024, 08:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-01-31 08:15
Updated : 2025-05-29 15:15
NVD link : CVE-2024-23775
Mitre link : CVE-2024-23775
CVE.ORG link : CVE-2024-23775
JSON object : View
Products Affected
                arm
- mbed_tls
CWE
                
                    
                        
                        CWE-190
                        
            Integer Overflow or Wraparound
