CVE-2014-2898: Critical severity wolfssl wolfmqtt vulnerability
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSLread function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2014-2898.
What is the severity of CVE-2014-2898?
The severity of CVE-2014-2898 is critical, with a severity value of 9.8.
What software is affected by CVE-2014-2898?
wolfSSL CyaSSL versions up to 2.9.0 are affected by CVE-2014-2898.
How does CVE-2014-2898 impact the system?
CVE-2014-2898 allows remote attackers to trigger an out-of-bounds read, leading to unspecified impact.
Are there any references for CVE-2014-2898?
Yes, here are some references for CVE-2014-2898: [1](http://seclists.org/oss-sec/2014/q2/126), [2](http://seclists.org/oss-sec/2014/q2/130), [3](http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html).