Affected packages

Git / github.com/armmbed/mbedtls

Affected ranges

Type
GIT
Repo
https://github.com/armmbed/mbedtls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.1.11"
        },
        {
            "introduced": "2.7.0"
        },
        {
            "fixed": "2.7.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.8.0-rc1"
        }
    ]
}
Type
GIT
Repo
https://github.com/mbed-tls/mbedtls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

Other
beta-oob-2
list
mbedos-2016q1-oob1
mbedos-2016q1-oob2
mbedos-2016q1-oob3
mbedos-release-15-11
mbedos-techcon-oob2
mbedos-16.*
mbedos-16.01-release
mbedos-16.03-release
mbedtls-1.*
mbedtls-1.3.10
mbedtls-1.4-dtls-preview
mbedtls-2.*
mbedtls-2.0.0
mbedtls-2.1.0
mbedtls-2.1.1
mbedtls-2.1.2
mbedtls-2.2.0
mbedtls-2.2.1
mbedtls-2.3.0
mbedtls-2.4.0
mbedtls-2.5.0
mbedtls-2.5.1
mbedtls-2.6.0
mbedtls-2.6.0-rc1
mbedtls-2.7.0
mbedtls-2.7.0-rc1
mbedtls-2.8.0-rc1
polarssl-1.*
polarssl-1.2.0
polarssl-1.2.1
polarssl-1.2.2
polarssl-1.2.3
polarssl-1.2.4
polarssl-1.2.5
polarssl-1.2.6
polarssl-1.3.0
polarssl-1.3.0-rc0
polarssl-1.3.1
polarssl-1.3.2
polarssl-1.3.3
polarssl-1.3.4
polarssl-1.3.5
polarssl-1.3.6
polarssl-1.3.7
polarssl-1.3.8
polarssl-1.3.9
yotta-2.*
yotta-2.2.1
yotta-2.2.2
yotta-2.2.3
yotta-2.3.0
yotta-2.3.1

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    }
]
vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2018-9989-33b2e7ed",
        "target": {
            "file": "library/ssl_cli.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "117461203888014430861683533234656718512",
                "243825661406862980169231204533098741260",
                "2493167677520519019066058455255881707"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/mbed-tls/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd5629e"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2018-9989-422b6ae2",
        "target": {
            "file": "library/ssl_cli.c",
            "function": "ssl_parse_server_psk_hint"
        },
        "digest": {
            "length": 505.0,
            "function_hash": "314921054803960153312991629036160735432"
        },
        "signature_version": "v1",
        "source": "https://github.com/mbed-tls/mbedtls/commit/740b218386083dc708ce98ccc94a63a95cd5629e"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9989.json"