wolfSSL.wolfssl is vulnerable to Integer Overflow or Wraparound
12
Low Risk
wolfssl_add_to_chain can integer-overflow the allocation size for certificate chain storage, leading to heap corruption when extra chain certificates are loaded through compatibility APIs enabled by certain OpenSSL-style build options. The issue is not remotely exploitable without a compromised loader of certificates. The fix validates sizes before writing chain data.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Integer Overflow or Wraparound in versions 0.0.1 - 5.8.4.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant