CVE-2022-46505 Information

Description

An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.

Reference

https://github.com/SmallTown123/details-for-CVE-2022-46505 https://smalltown123.notion.site/MatrixSSL-session-resume-bug-a0

Share on: