Executive brief
MatrixSSL is a lightweight TLS/SSL library used to secure communications in embedded devices and applications. A vulnerability in how it handles certain cryptographic keys allows a remote attacker to crash the service by sending a specially crafted value during the initial connection handshake. This results in a denial of service, preventing legitimate users from establishing secure connections to the affected device or application.
Technical details
A denial of service vulnerability exists in the MatrixSSL bignum library within the pstm_reverse function. The function fails to properly handle zero-sized inputs, leading to an integer underflow of a length variable and a subsequent invalid memory read. This can be triggered remotely during an RSA key exchange if an attacker provides a zero value or a value equal to the key's modulus as the secret key. The resulting crash terminates the process. The issue was addressed in MatrixSSL version 3.8.4.
Affected products
- MatrixSSL MatrixSSL before 3.8.4
Timeline
- 2016-07-31: disclosed: Initial public disclosure by Hanno Böck (The Fuzzing Project)
- 2016-08-01: patched: Fixed in MatrixSSL version 3.8.4
- 2017-01-13: advisory: NVD publication date