wolfSSL.wolfssh is vulnerable to Out-of-bounds Read
51
Medium Risk
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger this issue by supplying a crafted SCP path containing /./ sequences, causing a one-byte heap over-read.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssh is vulnerable to Out-of-bounds Read in versions 0.0.1 - 1.4.21.
Upgrade the wolfSSL.wolfssh library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant