CVE-2014-2896
Summary
| CVE | CVE-2014-2896 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-28 16:15:00 UTC |
| Updated | 2020-02-04 19:15:00 UTC |
| Description | The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wolfSSL Security Advisory: April 9, 2014 - wolfSSL | CONFIRM | www.wolfssl.com | Vendor Advisory |
| oss-sec: CVE ids for CyaSSL 2.9.4? | MISC | seclists.org | Mailing List, Third Party Advisory |
| wolfSSL - Docs | CyaSSL ChangeLog | CONFIRM | www.wolfssl.com | Vendor Advisory |
| oss-sec: Re: CVE ids for CyaSSL 2.9.4? | MISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.