Updated mbedtls packages fix security vulnerability
Publication date: 03 Jan 2018Modification date: 03 Jan 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-14032
Description
ARM mbed TLS before 1.3.21, 2.1.x before 2.1.9 and 2.x before 2.6.0, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates (CVE-2017-14032).
References
- https://bugs.mageia.org/show_bug.cgi?id=21645
- https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-02
- https://tls.mbed.org/tech-updates/releases/mbedtls-2.6.0-2.1.9-and-1.3.21-released
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BIDCXCILJ7BZS2GBSR75NMKRUNLQD3R5/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14032
SRPMS
5/core
- mbedtls-1.3.21-1.mga5
6/core
- mbedtls-2.6.0-1.mga6