CVE-2020-25023

CRITICAL

Noise-java < 2020-08-27 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.0063
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125 CWE-787
Status published
Products (1)
noise-java_project/noise-java < 2020-08-27
Published Sep 04, 2020
Tracked Since Feb 18, 2026