Release date:
Updated on:
Affected Systems:
CyaSSL <2.9.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66780
CyaSSL is a small portable embedded SSL programming library for embedded system developers.
In versions earlier than CyaSSL 2.9.4, there are multiple security vulnerabilities such as indirect NULL pointer reference, out-of-bounds memory reading, And X.509 unknown certificates, these vulnerabilities can be exploited maliciously to cause memory corruption and arbitrary code execution.
<* Source: Ivan Fratric (ifsecure@gmail.com)
Link: http://secunia.com/advisories/57743/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
CyaSSL
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.yassl.com/yaSSL/Products-cyassl.html
Http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html
Http://www.yassl.com/forums/topic539-cyassl-294-released.html