Executive brief
MatrixSSL is a lightweight security library used to provide encrypted communications for embedded devices and applications. A flaw in its mathematical processing allows a remote attacker to crash a server or device by sending a specially crafted zero-value during the initial connection handshake. This results in a denial of service, potentially disrupting secure communications and device availability.
Technical details
A vulnerability exists in the pstm_exptmod function within MatrixSSL's bignum library. The function fails to properly handle a base value of zero during modular exponentiation, leading to an invalid free operation and a subsequent application crash. This can be triggered remotely by an unauthenticated attacker during cryptographic handshakes, such as RSA key exchanges, where the client provides the base value. The issue was addressed in version 3.8.4, though the fix involves returning an error for zero-base inputs rather than supporting them.
Affected products
- MatrixSSL MatrixSSL before 3.8.4
Timeline
- 2016-07-31: disclosed: Public disclosure by Hanno Böck (The Fuzzing Project)
- 2016-07-31: patched: Fixed in MatrixSSL version 3.8.4
- 2017-01-13: advisory: NVD publication date