wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.
| Vendor | Product | Versions |
|---|---|---|
| wolfssl | wolfssl | 0 |
Updated description with new technical details, changed severity to HIGH, and added affected version 5.9.0.
Initial creation