VulnerabilityModified
CVE-2014-2896
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.
CRITICAL 9.8EPSS 2.77%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.77% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- wolfssl/wolfssl
- Source
- cve@mitre.org
References
- http://seclists.org/oss-sec/2014/q2/126Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q2/130Mailing List, Third Party Advisory
- http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.htmlVendor Advisory
- http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.htmlVendor Advisory
- http://seclists.org/oss-sec/2014/q2/126Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q2/130Mailing List, Third Party Advisory
- http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.htmlVendor Advisory
- http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.