An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2826-1 | mbedtls security update |
Debian DLA |
DLA-3249-1 | mbedtls security update |
EUVD |
EUVD-2020-23961 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:30:08.223Z
Reserved: 2021-08-23T00:00:00
Link: CVE-2020-36475
No data.
Status : Modified
Published: 2021-08-23T02:15:06.930
Modified: 2024-11-21T05:29:37.603
Link: CVE-2020-36475
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD