Skip to content

Conversation

@ltcdCai
Copy link

@ltcdCai ltcdCai commented Jul 19, 2024

Contact Details
[email protected]

What happened?
我通过使用V1SCAN(一个扫描存在于复用代码中1-Day漏洞的工具),发现您的项目中Huawei_LiteOS/components/security/mbedtls/mbedtls-2.6.0/library/ssl_cli.c文件中的ssl_parse_server_key_exchange函数可能存在类型为CWE-125 OOB的漏洞,相关触发逻辑类似GHSA-h9j8-4v77-hmr3, 具体参考链接如下:

CVE-2018-9988:
NVD说明链接:
https://nvd.nist.gov/vuln/detail/CVE-2018-9988
commit修复链接:
Mbed-TLS/mbedtls@027f84c

@flying-yes
Copy link

flying-yes commented Apr 1, 2025 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants