CVE-2022-25638

CVE-2022-25638

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.

Source: CVE-2022-25638

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다