A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
References
Link | Resource |
---|---|
https://github.com/ARMmbed/mbedtls/issues/5136 | Exploit Issue Tracking Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html | Mailing List Third Party Advisory |
Information
Published : 2022-03-24 11:15
Updated : 2023-02-02 11:59
NVD link : CVE-2021-43666
Mitre link : CVE-2021-43666
JSON object : View
CWE
Products Affected
debian
- debian_linux
arm
- mbed_tls