wolfSSL.wolfssl is vulnerable to Buffer overflow (stack based)
22
Low Risk
wc_PKCS7_EncodeSignedData and wc_PKCS7_EncodeSignedData_ex write signed attributes into a fixed-size array when encoding PKCS#7 SignedData; more than seven signed attributes causes a stack out-of-bounds write. Only custom PKCS#7 signing with many attributes triggers the issue. The fix enforces limits or sizing so the buffer cannot be overrun.
You are affected if you are using a version that falls within the vulnerable range.
wolfSSL.wolfssl is vulnerable to Buffer overflow (stack based) in versions 0.0.1 - 5.8.4.
Upgrade the wolfSSL.wolfssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant