CVE-2022-43974

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
09/01/2023
Last modified:
06/03/2025

Description

MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:* 4.0.0 (including) 4.6.0 (excluding)