PT-2020-7640 · Wolfssl · Cyassl

Ivan Fratric

·

Published

2020-01-28

·

Updated

2020-02-04

·

CVE-2014-2898

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wolfSSL CyaSSL versions prior to 2.9.4
Description The issue allows remote attackers to have an unspecified impact via multiple calls to the CyaSSL read function, which triggers an out-of-bounds read when an error occurs. This is related to not checking the return code and MAC verification failure.
Recommendations For versions prior to 2.9.4, update to version 2.9.4 or later to resolve the issue. As a temporary workaround, consider adding checks for the return code of the CyaSSL read function and ensuring proper MAC verification to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2898

Affected Products

Cyassl