Home
HIGH: 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 5.9.1
affected
Description
Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
Problem types
CWE-122 Heap-based Buffer Overflow
Product status
Any version before 5.9.1
Credits
Sunwoo Lee, Korea Institute of Energy Technology (KENTECH)
Seunghyun Yoon, Korea Institute of Energy Technology (KENTECH)
References
github.com/wolfssl/wolfssl/pull/10076