Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMatrixssl
APPMatrixssl≤ 3.8.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEXSSMemory
CWE
References
Related vulnerabilities
CVE-2019-14431CRITICAL9.8PL ✓same product
MatrixSSL DTLS: heap buffer overflow umożliwiający RCE
CVE-2019-13470CRITICAL9.8PL ✓same product
MatrixSSL: odczyt poza granicami bufora podczas przetwarzania ASN.1
CVE-2019-10914CRITICAL9.8PL ✓same product
Stack-based buffer overflow w MatrixSSL podczas weryfikacji certyfikatu X.509
CVE-2017-2781CRITICAL9.8PL ✓same product
Przepełnienie bufora heap w parsowaniu certyfikatów X509 w MatrixSSL
CVE-2017-2780CRITICAL9.8PL ✓same product
Heap buffer overflow w parsowaniu certyfikatów X.509 w MatrixSSL