An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Link | Tags |
---|---|
https://smalltown123.notion.site/MatrixSSL-session-resume-bug-a0 | permissions required vendor advisory |
https://github.com/SmallTown123/details-for-CVE-2022-46505 | third party advisory exploit |