Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-35409
Description:An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2022.0415  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-35409
[debian-lts-announce] 20221225 [SECURITY] [DLA 3249-1] mbedtls security update
https://lists.debian.org/debian-lts-announce/2022/12/msg00036.html
https://github.com/Mbed-TLS/mbedtls/releases
https://github.com/Mbed-TLS/mbedtls/releases
https://mbed-tls.readthedocs.io/en/latest/security-advisories/advisories/mbedtls-security-advisory-2022-07.html
https://mbed-tls.readthedocs.io/en/latest/security-advisories/advisories/mbedtls-security-advisory-2022-07.html




© 1998-2025 E-Soft Inc. All rights reserved.