Sploitus

CVE-2019-18840

No indexed exploits for CVE-2019-18840 yet

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow inside the DecodedCert structure in GetName in wolfcrypt/src/asn.c because the domain name location index is mishandled. Because a pointer is overwritten, there is an invalid free.

Affected products
Wolfssl
Wolfssl
≤ 4.2.0c
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
2.0% (78th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2019-11-09
CVE-2019-18840 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-18840 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-18840 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.