Логотип exploitDog
bind:CVE-2019-18840
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-18840

Количество 4

Количество 4

ubuntu логотип

CVE-2019-18840

около 6 лет назад

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-18840

около 6 лет назад

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-18840

около 6 лет назад

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of me ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42mp-7xj4-8whx

больше 3 лет назад

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-18840

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-18840

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-18840

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of me ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
github логотип
GHSA-42mp-7xj4-8whx

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу