Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
wolfSSL CyaSSL 缓冲区错误漏洞
Vulnerability Description
wolfSSL(前称CyaSSL)是美国wolfSSL公司的一个针对嵌入式系统开发人员使用的小的、可移植的嵌入式SSL编程库。 wolfSSL CyaSSL 2.9.4之前版本中存在缓冲区错误漏洞。远程攻击者可通过重复调用CyaSSL_read函数而不检查返回值利用该漏洞导致MAC验证失败。
CVSS Information
N/A
Vulnerability Type
N/A