CVE-2024-1545

Name
CVE-2024-1545
Description
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/wolfSSL/wolfssl/releases/tag/v5.7.0-stable
facts@wolfssl.com https://github.com/wolfSSL/wolfssl/pull/7167

Match rules

CPE URI Source package Min version Max version
wolfcrypt >= 0 <= 5.6.6
cpe:2.3:a:wolfssl:wolfcrypt:*:*:*:*:*:*:*:* wolfcrypt >= 0 <= 5.6.6
cpe:2.3:a:wolfssl:wolfssl:5.6.6:*:*:*:*:*:*:* wolfssl == None == 5.6.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wolfssl edge-community 5.7.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
wolfssl edge-community 5.6.6-r0 None possibly vulnerable
wolfssl 3.22-community 5.7.0-r0 None fixed
wolfssl 3.21-community 5.7.0-r0 None fixed
wolfssl 3.20-community 5.7.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed