#VU84840 Out-of-bounds read in wolfSSL - CVE-2023-6936
Published: December 28, 2023
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing a malformed ClientHello message in servers connecting over TLS 1.3 when the optional WOLFSSL_CALLBACKS has been defined. A remote attacker can trigger an out-of-bounds read error and read contents of memory on the system.