OSV 1.4.0 · unreviewed · 修改于 2022-01-28 08:04
发布时间
2022-01-19 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-19 05:15
源文件
advisories/unreviewed/2022/01/GHSA-xx9h-ppjx-3rjx/GHSA-xx9h-ppjx-3rjx.json
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c.
该公告没有提供结构化的受影响软件包信息。