Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2w9-2vv2-hrmq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

EPSS

Процентиль: 77%
0.01008
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

CVSS3: 9.8
debian
около 6 лет назад

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecifie ...

EPSS

Процентиль: 77%
0.01008
Низкий