wolfSSL.wolfssh is vulnerable to Out-of-bounds Read
51
Medium Risk
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger this issue by supplying a crafted SCP path containing /./ sequences, causing a one-byte heap over-read.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssh is vulnerable to Out-of-bounds Read in versions 0.0.1 - 1.4.21.
Upgrade the wolfSSL.wolfssh library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant