VDB

DEBIAN-CVE-2020-36476

DEBIAN-CVE-2020-36476 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:13mbedtls0, 0, 0
Debian:11mbedtls0, 0, 0
Debian:12mbedtls0, 0, 0
Debian:14mbedtls0, 0, 0

Timeline

  • Aug 23, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›