#VU50252 Out-of-bounds write in wolfSSL - CVE-2020-36177
Published: January 6, 2021 / Updated: February 2, 2021
wolfSSL
wolfSSL
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input for certain relationships between key size and digest size within the RsaPad_PSS() function in wolfcrypt/src/rsa.c in wolfSSL. A remote attacker can send specially crafted data to the application, trigger out-of-bounds write and execute arbitrary code on the target system.
Remediation
External links
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=26567
- https://github.com/wolfSSL/wolfssl/commit/63bf5dc56ccbfc12a73b06327361687091a4c6f7
- https://github.com/wolfSSL/wolfssl/commit/fb2288c46dd4c864b78f00a47a364b96a09a5c0f
- https://github.com/wolfSSL/wolfssl/pull/3426
- https://github.com/wolfSSL/wolfssl/releases/tag/v4.6.0-stable