Vulnerability CVE-2022-46505


Published: 2023-01-18

Description:
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.

 References:
https://github.com/SmallTown123/details-for-CVE-2022-46505
https://smalltown123.notion.site/MatrixSSL-session-resume-bug-a0

Copyright 2024, cxsecurity.com

 

Back to Top