RSS   Vulnerabilities for 'Wolfssl'   RSS

2020-01-28
 
CVE-2014-2898

CWE-125
 

 
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

 
 
CVE-2014-2897

CWE-125
 

 
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.

 
 
CVE-2014-2896

CWE-125
 

 
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.

 
2019-12-25
 
CVE-2019-19963

NVD-CWE-Other
 

 
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

 
 
CVE-2019-19962

CWE-327
 

 
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

 
 
CVE-2019-19960

NVD-CWE-Other
 

 
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.

 
2019-12-11
 
CVE-2019-14317

CWE-311
 

 
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c fixes two bits of the generated nonces.

 
2019-11-21
 
CVE-2014-2904

CWE-287
 

 
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

 
 
CVE-2014-2902

CWE-295
 

 
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

 
 
CVE-2014-2901

CWE-295
 

 
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

 


Copyright 2020, cxsecurity.com

 

Back to Top