nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-2800 CVE-2017-2800
CRITICAL
wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One
Record summary
CVE-2017-2800 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wolfSSLBrowse wolfSSL / wolfSSL | CVE List | 3.10.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBwolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-OneExploitDB exploitby TalosNot analyzed1 file
References
3talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0293 41984exploit
https://www.exploit-db.com/exploits/41984