Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10657

Опубликовано: 02 мая 2018
Источник: debian

Описание

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
matrix-synapsefixed0.28.1+dfsg-1package

Примечания

  • https://github.com/matrix-org/synapse/commit/33f469ba19586bbafa0cf2c7d7c35463bdab87eb

  • https://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

CVSS3: 7.5
nvd
больше 8 лет назад

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

CVSS3: 7.5
github
больше 4 лет назад

Matrix Synapse DoS