Source: wolfssl
Version: 3.15.3+dfsg-2
Severity: grave
Tags: patch security upstream
Forwarded: https://github.com/wolfSSL/wolfssl/pull/1950

Hi,

The following vulnerability was published for wolfssl.

CVE-2018-16870[0]:
| It was found that wolfssl before 3.15.7 is vulnerable to a new variant
| of the Bleichenbacher attack to perform downgrade attacks against TLS.
| This may lead to leakage of sensible data.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-16870
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16870
[1] https://github.com/wolfSSL/wolfssl/pull/1950

Regards,
Salvatore

Reply via email to