Vulnerability Bulletins

DSA-3967 mbedtls - security update

   
Affected software Debian
 
An authentication bypass vulnerability was discovered in mbed TLS, alightweight crypto and SSL/TLS library, when the authentication mode isconfigured as optional. A remote attacker can take advantage of thisflaw to mount a man-in-the-middle attack and impersonate an intendedpeer via an X.509 certificate chain with many intermediates.

More info:

https://www.debian.org/security/2017/dsa-3967