TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/matrixssl/matrixssl/blob/master/CHANGES.md | release notes vendor advisory |
http://www.openwall.com/lists/oss-security/2016/08/19/8 | third party advisory mailing list |
http://www.securityfocus.com/bid/91488 | vdb entry |