{"id":"MGASA-2017-0094","summary":"Updated mbedtls packages fix security vulnerability","details":"In mbedTLS before 1.3.19, if a malicious peer supplies a certificate with\na specially crafted secp224k1 public key, then an attacker can cause the\nserver or client to attempt to free block of memory held on stack.\nDepending on the platform, this could result in a Denial of Service\n(client crash) or potentially could be exploited to allow remote code\nexecution with the same privileges as the host application\n(CVE-2017-2784).\n\nThe mbedtls package has been updated to version 1.3.19, fixing this issue\nas well as other security issues and bugs.\n","modified":"2026-04-16T01:48:17.493680508Z","published":"2017-03-27T21:27:33Z","upstream":["CVE-2017-2784"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0094.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=20561"},{"type":"WEB","url":"https://tls.mbed.org/tech-updates/releases/mbedtls-2.4.2-2.1.7-and-1.3.19-released"},{"type":"ADVISORY","url":"https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-01"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2017-03/msg00072.html"}],"affected":[{"package":{"name":"mbedtls","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/mbedtls?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.19-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0094.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}