漏洞标题
N/A
漏洞描述信息
TLSlite-ng版本0.7.3及其更早版本中,由于d7b288316bca7bcdd082e6ccff5491e241305233提交包含CWE-354:TLS实现中 integrity Check 值验证不正确漏洞,tlslite/utils/constanttime.py:ct_check_cbc_mac_and_pad();行“end_pos = data_len - 1 - mac.digest_size”,攻击者可能会修改TLS加密密文,而接收 TLSlite-ng 无法检测。这种攻击似乎可以通过中间人攻击在网络安全中实现。在提交3674815d1b0f7484454995e2737a352e0a6a93d8之后,该漏洞已被修复。
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper Validation of Integrity Check Value vulnerability in TLS implementation, tlslite/utils/constanttime.py: ct_check_cbc_mac_and_pad(); line "end_pos = data_len - 1 - mac.digest_size" that can result in an attacker manipulating the TLS ciphertext which will not be detected by receiving tlslite-ng. This attack appears to be exploitable via man in the middle on a network connection. This vulnerability appears to have been fixed after commit 3674815d1b0f7484454995e2737a352e0a6a93d8.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
tlslite-ng 输入验证错误漏洞
漏洞描述信息
tlslite-ng是一个基于Python的实现了SSL和TSL加密协议的开源库。 tlslite-ng 0.7.3及之前版本中的TLS实现存在输入验证漏洞。远程攻击者可通过实施中间人攻击利用该漏洞绕过安全检测。
CVSS信息
N/A
漏洞类别
输入验证错误