Eclipse tinydtls是美国Eclipse基金会开源的一个轻量级DTLS协议库。 Eclipse tinydtls b3efd41ad111a4920f599f51ffa4f5e9f1e72221之前版本存在缓冲区错误漏洞,该漏洞源于check_server_certificate()函数中存在越界读取问题,在uint24读取、memcmp和memcpy操作之前缺少缓冲区长度验证,未经身份验证的攻击者可以通过构造带有特定fragment_length值的Certificate握手消息触发超出有效
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse tinydtls | < b3efd41ad111a4920f599f51ffa4f5e9f1e72221 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse tinydtls | 0 ~ b3efd41ad111a4920f599f51ffa4f5e9f1e72221 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet