Skip to content

Conversation

@yannaingtun
Copy link

Description
This PR fixes a security vulnerability in sig_verify() function that was cloned from axTLS but did not receive the security patch.
The original issue was reported and fixed in the axTLS repository under commit 5efe2947ab45e81d84b5f707c51d1c64be52f36c. This PR applies a similar patch to eliminate the buffer overflow vulnerability.

References
https://nvd.nist.gov/vuln/detail/CVE-2018-16149
https://nvd.nist.gov/vuln/detail/CVE-2018-16150
igrr/axtls-8266@5efe294

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant