Description
Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-experimental and --enable-dual-alg-certs is used when building wolfSSL.
Problem types
Product status
Any version before 5.9.1
Credits
Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) for testing
Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) for testing
Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH) for testing
References
github.com/wolfSSL/wolfssl/pull/10079