Due to a security advisory released on February 1st 2018[1], it's advisable to update mbedTLS to 2.7.0. The vulnerability, identified as CVE-2018-0488 and CVE-2018-0487, risk remote code execution when truncated HMAC is enabled or when verifying RSASSA-PSS signatures. [1] https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2018-01 Fixes: #6025 Signed-off-by: Kumar Gala <kumar.gala@linaro.org> |
||
|---|---|---|
| .. | ||
| mbedtls | ||
| tinycrypt | ||
| CMakeLists.txt | ||
| Kconfig | ||