Stack Pointer Vulnerability in ARM mbed TLS Certificate Parsing
CVE-2017-2784

8.1HIGH

Key Information:

Vendor

Arm

Status
Vendor
CVE Published:
20 April 2017

What is CVE-2017-2784?

A critical flaw exists in the x509 certificate parsing code of ARM's mbed TLS, allowing an attacker to manipulate the memory stack. When the library processes a specifically crafted x509 certificate, it risks an invalid stack pointer free, particularly enabling potential remote code execution. Attackers can exploit this by acting as either server or client, delivering malicious certificates to applications that utilize the affected mbed TLS versions. This vulnerability poses a significant security risk to systems relying on these versions of mbed TLS for secure communication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

mbed TLS 2.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.