Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-24613

Опубликовано: 24 авг. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.9
CVSS3: 6.8

Описание

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

4.5.0+dfsg-2
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

4.5.0+dfsg-2
esm-apps/noble

not-affected

4.5.0+dfsg-2
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

not-affected

4.5.0+dfsg-2

Показывать по

4.9 Medium

CVSS2

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
больше 5 лет назад

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

CVSS3: 6.8
debian
больше 5 лет назад

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_C ...

github
больше 3 лет назад

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

4.9 Medium

CVSS2

6.8 Medium

CVSS3