Описание
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.
Ссылки
- Release NotesThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 4.6.0 (исключая)
cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.18851
Средний
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-190
CWE-190
Связанные уязвимости
CVSS3: 8.1
debian
около 3 лет назад
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDeco ...
EPSS
Процентиль: 95%
0.18851
Средний
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-190
CWE-190