CVE-2022-42905
published 2022-11-07CVE-2022-42905: In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.96%
78.1th percentile
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wolfssl | < wolfssl 5.5.3-1 (bookworm) | wolfssl 5.5.3-1 (bookworm) |
| wolfssl | wolfssl | < 5.5.2 | 5.5.2 |
| wolfssl | wolfssl | >= 0 < 4.6.0+p1-0+deb11u2 | 4.6.0+p1-0+deb11u2 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
| wolfssl | wolfssl | >= 0 < 5.5.3-1 | 5.5.3-1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-42905: wolfssl - In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALL...
vendor_debian·2022·CVSS 9.1
CVE-2022-42905 [CRITICAL] CVE-2022-42905: wolfssl - In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALL...
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)
Scope: local
bookworm: resolved (fixed in 5.5.3-1)
bullseye: resolved (fixed in 4.6.0+p1-0+deb11u2)
forky: resolved (fixed in 5.5.3-1)
sid: resolved (fixed in 5.5.3-1)
trixie: resolved (fixed in 5.5.3-1)
GHSA
GHSA-h6wv-v27f-f93r: In wolfSSL before 5
ghsa_unreviewed·2022-11-07
CVE-2022-42905 [CRITICAL] CWE-125 GHSA-h6wv-v27f-f93r: In wolfSSL before 5
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)
OSV
CVE-2022-42905: In wolfSSL before 5
osv·2022-11-07·CVSS 9.1
CVE-2022-42905 [CRITICAL] CVE-2022-42905: In wolfSSL before 5
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)
No detection rules found.
No public exploits indexed.
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152, CVE-2022-38153, CVE-2022-39173, and CVE-2022-42905. The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin. This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France, it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), adding mo
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152 , CVE-2022-38153 , CVE-2022-39173 , and CVE-2022-42905 . The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin . This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France , it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), add
http://packetstormsecurity.com/files/170610/wolfSSL-WOLFSSL_CALLBACKS-Heap-Buffer-Over-Read.htmlhttp://seclists.org/fulldisclosure/2023/Jan/11https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/https://github.com/wolfSSL/wolfssl/releaseshttps://github.com/wolfSSL/wolfssl/releases/tag/v5.5.2-stablehttps://www.wolfssl.com/docs/security-vulnerabilities/http://packetstormsecurity.com/files/170610/wolfSSL-WOLFSSL_CALLBACKS-Heap-Buffer-Over-Read.htmlhttp://seclists.org/fulldisclosure/2023/Jan/11https://blog.trailofbits.com/2023/01/12/wolfssl-vulnerabilities-tlspuffin-fuzzing-ssh/https://github.com/wolfSSL/wolfssl/releaseshttps://github.com/wolfSSL/wolfssl/releases/tag/v5.5.2-stablehttps://www.wolfssl.com/docs/security-vulnerabilities/
2022-11-07
Published