Candidate: CVE-2020-12457 PublicDate: 2020-08-21 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12457 https://github.com/wolfSSL/wolfssl/pull/2927 https://github.com/wolfSSL/wolfssl/releases/tag/v4.5.0-stable Description: An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server becomes stuck in the ProcessReply() loop, i.e., a denial of service. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_wolfssl: upstream: https://github.com/wolfSSL/wolfssl/commit/df1b7f34f173cfc2968ce12e8fcd2fd8bcc61a59 (v4.5.0-stable) upstream_wolfssl: released (v4.5.0-stable) precise/esm_wolfssl: DNE trusty_wolfssl: ignored (out of standard support) trusty/esm_wolfssl: DNE xenial_wolfssl: ignored (end of standard support, was needed) bionic_wolfssl: needed focal_wolfssl: needed groovy_wolfssl: not-affected (4.5.0+dfsg-2) hirsute_wolfssl: not-affected (4.5.0+dfsg-2) impish_wolfssl: not-affected (4.5.0+dfsg-2) jammy_wolfssl: not-affected (4.5.0+dfsg-2) devel_wolfssl: not-affected (4.5.0+dfsg-2)