CVE-2017-2782
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- matrixssl/matrixssl
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/99249Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0278Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99249Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0278Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.