PT-2020-7640 · Wolfssl · Cyassl
Ivan Fratric
·
Published
2020-01-28
·
Updated
2020-02-04
·
CVE-2014-2898
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
wolfSSL CyaSSL versions prior to 2.9.4
Description
The issue allows remote attackers to have an unspecified impact via multiple calls to the CyaSSL read function, which triggers an out-of-bounds read when an error occurs. This is related to not checking the return code and MAC verification failure.
Recommendations
For versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider adding checks for the return code of the CyaSSL read function and ensuring proper MAC verification to minimize the risk of exploitation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyassl