Skip to content

Conversation

yannaingtun
Copy link

Description
This PR fixes a security vulnerability in sig_verify() function that was cloned from axTLS but did not receive the security patch.
The original issue was reported and fixed in the axTLS repository under commit 5efe2947ab45e81d84b5f707c51d1c64be52f36c. This PR applies a similar patch to eliminate the buffer overflow vulnerability.

References
https://nvd.nist.gov/vuln/detail/CVE-2018-16149
https://nvd.nist.gov/vuln/detail/CVE-2018-16150
igrr/axtls-8266@5efe294

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant