Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv8r-m42c-756r

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

EPSS

Процентиль: 47%
0.00241
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

CVSS3: 6.5
nvd
больше 8 лет назад

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

CVSS3: 6.5
debian
больше 8 лет назад

An integer overflow vulnerability exists in the X509 certificate parsi ...

EPSS

Процентиль: 47%
0.00241
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-190