CVE-2019-18840
published 2019-11-09CVE-2019-18840: In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.97%
78.2th percentile
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 4.2.0+dfsg-3 (bookworm) | wolfssl 4.2.0+dfsg-3 (bookworm) |
| wolfssl | wolfssl | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| wolfssl | wolfssl | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| wolfssl | wolfssl | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| wolfssl | wolfssl | >= 0 < 4.2.0+dfsg-3 | 4.2.0+dfsg-3 |
| wolfssl | wolfssl | 4.1.0 – 4.2.0c | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-18840: wolfssl - In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory acces...
vendor_debian·2019·CVSS 7.5
CVE-2019-18840 [HIGH] CVE-2019-18840: wolfssl - In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory acces...
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
Scope: local
bookworm: resolved (fixed in 4.2.0+dfsg-3)
bullseye: resolved (fixed in 4.2.0+dfsg-3)
forky: resolved (fixed in 4.2.0+dfsg-3)
sid: resolved (fixed in 4.2.0+dfsg-3)
trixie: resolved (fixed in 4.2.0+dfsg-3)
GHSA
GHSA-42mp-7xj4-8whx: In wolfSSL 4
ghsa_unreviewed·2022-05-24
CVE-2019-18840 [MEDIUM] GHSA-42mp-7xj4-8whx: In wolfSSL 4
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
OSV
CVE-2019-18840: In wolfSSL 4
osv·2019-11-09·CVSS 7.5
CVE-2019-18840 [HIGH] CVE-2019-18840: In wolfSSL 4
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
No detection rules found.
No public exploits indexed.
2019-11-09
Published