CVE-2017-8854: Buffer Overflow
Published May 9, 2017
·Updated
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file.
Affected Software
1 affected component
wolfSSL wolfssl<=3.10.0a
Remediation
Event History
May 9, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8854?
CVE-2017-8854 is classified as a high severity vulnerability due to the potential for remote code execution caused by a buffer overflow.
2
How do I fix CVE-2017-8854?
To resolve CVE-2017-8854, update to wolfSSL version 3.10.2 or later.
3
What kind of vulnerability is CVE-2017-8854?
CVE-2017-8854 is an out-of-bounds memory access vulnerability related to the handling of crafted DH parameters.
4
What happens if I exploit CVE-2017-8854?
Exploiting CVE-2017-8854 could allow an attacker to execute arbitrary code on the affected system.
5
Which versions of wolfSSL are affected by CVE-2017-8854?
Versions of wolfSSL prior to 3.10.2, specifically up to 3.10.0a, are affected by CVE-2017-8854.