PT-2024-15130 · Wolfssl+1 · Wolfssl+1
Lucca Hirschi
+3
·
Published
2024-02-20
·
Updated
2025-02-12
·
CVE-2023-6936
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL versions prior to 5.6.6
Description
The issue allows a malicious TLS client or network attacker to trigger a buffer over-read on the heap of 5 bytes if callback functions are enabled via the
WOLFSSL CALLBACKS flag. This flag is only intended for debugging purposes.Recommendations
For versions prior to 5.6.6, update to version 5.6.6 or later to resolve the issue. As a temporary workaround, consider disabling the
WOLFSSL CALLBACKS flag to prevent exploitation.Fix
Buffer Over-read
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Wolfssl