Impact
A heap based buffer overflow exists in pcpp::SSLClientHelloMessage::getHandshakeVersion, the function that parses the TLS ClientHello message. By manipulating the handshakeVersion argument, an attacker can overflow a heap buffer and achieve arbitrary code execution on the host. The vulnerability is exploitable remotely via a specially crafted TLS packet and is publicly disclosed. It has high complexity and is considered difficult to exploit, but the availability of a public exploit means it can be readily used by motivated threat actors.
Affected Systems
The affected product is seladb PcapPlusPlus version 25.05. The overflow occurs in the TLS Hello Handler component of the library. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires sending a crafted TLS ClientHello message and is considered difficult, the maximum impact is moderate, yet any system that processes TLS traffic with this version of PcapPlusPlus remains at risk until a patch is applied.
OpenCVE Enrichment