Home
LOW: 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 5.9.1
affected
Description
Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().
Problem types
Product status
Any version before 5.9.1
Credits
J Laratro (d0sf3t)
References
github.com/wolfssl/wolfssl/pull/10039