CVE-2023-6937 Affecting wolfssl package, versions <5.6.6-1.2
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-WOLFSSL-6139099
- published 23 Dec 2023
- disclosed 15 Feb 2024
Introduced: 23 Dec 2023
CVE-2023-6937 Open this link in a new tabHow to fix?
Upgrade Debian:unstable wolfssl to version 5.6.6-1.2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream wolfssl package and not the wolfssl package as distributed by Debian.
See How to fix? for Debian:unstable relevant fixed versions and status.
wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS messages using different keys into one (D)TLS record. The most extreme edge case is that, in (D)TLS 1.3, it was possible that an unencrypted (D)TLS 1.3 record from the server containing first a ServerHello message and then the rest of the first server flight would be accepted by a wolfSSL client. In (D)TLS 1.3 the handshake is encrypted after the ServerHello but a wolfSSL client would accept an unencrypted flight from the server. This does not compromise key negotiation and authentication so it is assigned a low severity rating.