漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
Improper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify
漏洞信息
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously could respond as ECDSA P256 being the accepted signature algorithm and the connection would continue with using ECDSA P256, if the client supports ECDSA P256.
漏洞信息
N/A
漏洞
输入验证不恰当
漏洞
wolfSSL 安全漏洞
漏洞信息
wolfSSL(CyaSSL)是美国wolfSSL公司的一个针对嵌入式系统开发人员使用的小的、可移植的嵌入式SSL编程库。 wolfSSL(CyaSSL) 5.8.2及之前版本存在安全漏洞,该漏洞源于TLS 1.3 CertificateVerify签名算法协商输入验证不当,可能导致签名算法降级。
漏洞信息
N/A
漏洞
N/A