CVE-2024-45158 | mbed TLS 3.6.0 mbedtls_ecdsa_der_to_raw/mbedtls_ecdsa_raw_to_der bits stack-based overflow
A vulnerability classified as critical has been found in mbed TLS 3.6.0. The affected element is the function mbedtls_ecdsa_der_to_raw/mbedtls_ecdsa_raw_to_der. This manipulation of the argument bits causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2024-45158. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.