漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
Vulnerability Description
A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read from an untrusted input without bounds validation, allowing an attacker to overflow fixed-size buffers and corrupt heap memory. A maliciously crafted session would need to be loaded from an external source to trigger this vulnerability. Internal sessions were not vulnerable.
CVSS Information
N/A
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
wolfSSL 安全漏洞
Vulnerability Description
wolfSSL(CyaSSL)是美国wolfSSL公司的一个针对嵌入式系统开发人员使用的小的、可移植的嵌入式SSL编程库。 wolfSSL存在安全漏洞,该漏洞源于wolfSSL_d2i_SSL_SESSION函数存在堆缓冲区溢出,当反序列化启用了SESSION_CERTS的会话数据时,可能导致攻击者溢出固定大小的缓冲区并损坏堆内存。
CVSS Information
N/A
Vulnerability Type
N/A