CVE-2014-2902: High severity wolfSSL wolfssl vulnerability
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-2902?
CVE-2014-2902 is a vulnerability in wolfssl before version 3.2.0 that allows an unauthorized CA certificate to sign other certificates.
How severe is CVE-2014-2902?
CVE-2014-2902 has a severity rating of 7.5 (high).
What software is affected by CVE-2014-2902?
wolfssl versions up to 3.2.0 and debian/wolfssl versions 4.6.0+p1-0+deb11u1 and 5.5.4-2 are affected by CVE-2014-2902.
How can I fix CVE-2014-2902?
To fix CVE-2014-2902, update wolfssl to version 3.2.0 or later or update debian/wolfssl to versions 4.6.0+p1-0+deb11u1 or 5.5.4-2.
Where can I find more information about CVE-2014-2902?
You can find more information about CVE-2014-2902 at the following references: [1] http://www.openwall.com/lists/oss-security/2014/04/18/2, [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=792646, [3] https://security-tracker.debian.org/tracker/CVE-2014-2902.