Bug#979534: wolfssl: CVE-2020-36177

2021-01-17 Thread Felix Lechner
Hi, On Thu, Jan 7, 2021 at 12:12 PM Salvatore Bonaccorso wrote: > > CVE-2020-36177[0]: This vulnerability will be fixed in the next couple of days via upload of version 4.6.0 to unstable. A backport of the fix is not possible (freeze notwithstanding). Also, the patches from #978676 do not

Bug#979534: wolfssl: CVE-2020-36177

2021-01-15 Thread Bastian Germann
On Thu, 07 Jan 2021 21:09:25 +0100 Salvatore Bonaccorso > The following vulnerability was published for wolfssl. CVE-2020-36177[0]: | RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out- | of-bounds write for certain relationships between key size and digest | size. If you

Bug#979534: wolfssl: CVE-2020-36177

2021-01-07 Thread Salvatore Bonaccorso
Source: wolfssl Version: 4.5.0+dfsg-4 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/wolfSSL/wolfssl/pull/3426 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for wolfssl.