Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6q89-vxvr-wgv2

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1
CVSS3: 5.3

Описание

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

EPSS

Процентиль: 17%
0.00257
Низкий

1 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

CVSS3: 5.3
nvd
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This affects wolfSSL 5.9.0 and earlier and was fixed in the 5.9.1 release.

CVSS3: 5.3
debian
около 1 месяца назад

The PKCS#7 decode path ignores the caller-supplied output buffer size ...

EPSS

Процентиль: 17%
0.00257
Низкий

1 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-120