Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh62-5q2g-qjmx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

EPSS

Процентиль: 59%
0.00378
Низкий

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 4 лет назад

In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

CVSS3: 4.9
nvd
больше 4 лет назад

In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

CVSS3: 4.9
debian
больше 4 лет назад

In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM f ...

CVSS3: 4.9
fstec
больше 4 лет назад

Уязвимость библиотеки SSL/TLS WolfSSL, связанная с раскрытием информации через несоответствие, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 59%
0.00378
Низкий

Дефекты

CWE-203