Vulnerabilities
Vulnerable Software
Wolfssl:  >> Wolfssl  >> 4.2.0c  Security Vulnerabilities
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."
CVSS Score
5.3
EPSS Score
0.013
Published
2020-06-25
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
CVSS Score
5.3
EPSS Score
0.01
Published
2019-12-25
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
CVSS Score
7.5
EPSS Score
0.009
Published
2019-12-25
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.
CVSS Score
5.3
EPSS Score
0.01
Published
2019-12-25
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.
CVSS Score
7.5
EPSS Score
0.02
Published
2019-11-09


Contact Us

Shodan ® - All rights reserved