CVE-2017-8855Wolfssl vulnerability

5 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 44.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 9
Latest updateMay 13

Description

wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wolfssl< wolfssl 3.12.0+dfsg-1 (bookworm)
Debianwolfssl/wolfssl< 3.12.0+dfsg-1+3
NVDwolfssl/wolfssl3.10.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9pgp-f7j2-6cwq: wolfSSL before 32022-05-13
OSV
CVE-2017-8855: wolfSSL before 32017-05-09

💥Exploits & PoCs

1
Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting2017-03-15

📋Vendor Advisories

1
Debian
CVE-2017-8855: wolfssl - wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH ...2017
CVE-2017-8855 — Debian Wolfssl vulnerability | cvebase