wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
[
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"166717417374588321458813928114453004118",
"100066283506131351387996469012373827165",
"261546692408925214412452524309330904915",
"340175888677556585777169330515393971171",
"334046187563482848033628567649019522681",
"204990480694242824373821406926180262354",
"58078628999482122902017988352386455451",
"15943859578411976128162647846380111970",
"33618659943274465574035882273229317353"
]
},
"id": "CVE-2021-38597-5198d99d",
"target": {
"file": "wolfcrypt/src/asn.c"
},
"signature_type": "Line",
"source": "https://github.com/wolfssl/wolfssl/commit/f93083be72a3b3d956b52a7ec13f307a27b6e093"
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"153261655079507998243035182815092040257",
"94397097935125013550427540131195665170",
"320149238350935993266883141139327796044",
"44782353481244881549460795752955312635"
]
},
"id": "CVE-2021-38597-617fcaf1",
"target": {
"file": "wolfssl/wolfcrypt/asn.h"
},
"signature_type": "Line",
"source": "https://github.com/wolfssl/wolfssl/commit/f93083be72a3b3d956b52a7ec13f307a27b6e093"
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 9655.0,
"function_hash": "125232856949344471807192566925669934083"
},
"id": "CVE-2021-38597-70dc61c3",
"target": {
"file": "wolfcrypt/src/asn.c",
"function": "ParseCertRelative"
},
"signature_type": "Function",
"source": "https://github.com/wolfssl/wolfssl/commit/f93083be72a3b3d956b52a7ec13f307a27b6e093"
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2542.0,
"function_hash": "255771284546534536757906501825746558559"
},
"id": "CVE-2021-38597-b66bd05f",
"target": {
"file": "wolfcrypt/src/asn.c",
"function": "DecodeBasicOcspResponse"
},
"signature_type": "Function",
"source": "https://github.com/wolfssl/wolfssl/commit/f93083be72a3b3d956b52a7ec13f307a27b6e093"
}
]