#VU45987 Resource management error in wolfSSL - CVE-2020-24585
Published: August 24, 2020
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources with the application within the DTLS handshake implementation in wolfSSL. Clear DTLS application_data messages in epoch 0 do not produce an out-of-order error. Instead, these messages are returned to the application.