CVE-2022-39173
published 2022-09-29CVE-2022-39173: In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.34%
90.2th percentile
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.5.3-1 (bookworm) | wolfssl 5.5.3-1 (bookworm) |
| wolfssl | wolfssl | < 5.5.1 | 5.5.1 |
| wolfssl | wolfssl | >= 0 < 4.6.0+p1-0+deb11u2 | 4.6.0+p1-0+deb11u2 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-39173: wolfssl - In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a ...
vendor_debian·2022·CVSS 7.5
CVE-2022-39173 [HIGH] CVE-2022-39173: wolfssl - In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a ...
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
Scope: local
bookworm: resolved (fixed in 5.5.3-1)
bullseye: resolved (fixed in 4.6.0+p1-0+deb11u2)
forky: resolved (fixed in 5.5.3-1)
sid: resolved (fixed in 5.5.3-1)
trixie: resolved (fixed in 5.5.3-1)
GHSA
GHSA-ww6v-6x26-hgfc: In wolfSSL before 5
ghsa_unreviewed·2022-09-30
CVE-2022-39173 [HIGH] CWE-120 GHSA-ww6v-6x26-hgfc: In wolfSSL before 5
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
OSV
CVE-2022-39173: In wolfSSL before 5
osv·2022-09-29·CVSS 7.5
CVE-2022-39173 [HIGH] CVE-2022-39173: In wolfSSL before 5
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher suites to trigger the buffer overflow. In total, two Client Hellos have to be sent: one in the resumed session, and a second one as a response to a Hello Retry Request message.
No detection rules found.
No public exploits indexed.
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152, CVE-2022-38153, CVE-2022-39173, and CVE-2022-42905. The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin. This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France, it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), adding mo
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152 , CVE-2022-38153 , CVE-2022-39173 , and CVE-2022-42905 . The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin . This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France , it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), add
http://packetstormsecurity.com/files/169600/wolfSSL-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2022/Oct/24https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/https://github.com/wolfSSL/wolfssl/releaseshttps://www.wolfssl.com/docs/security-vulnerabilities/http://packetstormsecurity.com/files/169600/wolfSSL-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2022/Oct/24https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/https://github.com/wolfSSL/wolfssl/releaseshttps://www.wolfssl.com/docs/security-vulnerabilities/
2022-09-29
Published