Heap-based buffer overflow in MatrixSSL - CVE-2017-2781
Published: June 26, 2017
MatrixSSL
Detailed vulnerability description
The vulnerability exists in the 'parsePolicyMappings' function in MatrixSSL due to heap-based buffer overflow when parsing the IssuerPolicy PolicyMappings extension. A remote attacker can supply a specially crafted x509 certificates in DER format containing OID value, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.