#VU45989 Infinite loop in wolfSSL - CVE-2020-12457
Published: August 24, 2020
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The
vulnerability exists due to improper change_cipher_spec (CCS) message
processing logic for TLS 1.3. A remote attacker can send
ChangeCipherSpec messages in a crafted way involving more than one in a
row and perform a denial of service (DoS) attack.