Dismissed
(no matching packages found)
by @ADMIN Activity log
- Created suggestion
- @ADMIN dismissed (no matching packages found)
Session Cache Restore — Arbitrary Free via Deserialized Pointer
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the cache and for the application to call specific session restore APIs.
Affected products
wolfSSL
- =<5.9.0