CVE-2022-43974: Buffer Overflow
Published Jan 9, 2023
·Updated
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.
Affected Software
1 affected component
MatrixSSL MatrixSSL>=4.0.0<4.6.0
Event History
Jan 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43974?
CVE-2022-43974 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-43974?
To fix CVE-2022-43974, upgrade MatrixSSL to version 4.6.0 or later.
3
What causes the vulnerability CVE-2022-43974?
CVE-2022-43974 is caused by an integer overflow in the matrixSslDecodeTls13 function.
4
Can CVE-2022-43974 be exploited remotely?
Yes, CVE-2022-43974 can be exploited remotely by sending a crafted TLS message.
5
Which versions of MatrixSSL are affected by CVE-2022-43974?
MatrixSSL versions 4.0.4 through 4.5.1 are affected by CVE-2022-43974.