cve/2020/CVE-2020-36476.md
2024-05-25 21:48:12 +02:00

728 B

CVE-2020-36476

Description

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

POC

Reference

No PoCs from references.

Github