MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/matrixssl/matrixssl/blob/3-8-6-open/CHANGES.md | patch third party advisory release notes |
https://www.kb.cert.org/vuls/id/396440 | third party advisory us government resource |
http://www.securityfocus.com/bid/93498 | third party advisory vdb entry |
http://www.tripwire.com/state-of-security/security-data-protection/cyber-security/flawed-matrixssl-code-highlights-need-for-better-iot-update-practices/ | third party advisory technical description |