Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-29189

Опубликовано: 21 мая 2022
Источник: debian
EPSS Низкий

Описание

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snowflakefixed2.2.0-1package

Примечания

  • https://github.com/pion/dtls/security/advisories/GHSA-cx94-mrg9-rq4j

  • https://github.com/pion/dtls/commit/a6397ff7282bc56dc37a68ea9211702edb4de1de (v2.1.4)

  • https://github.com/pion/dtls/releases/tag/v2.1.4

EPSS

Процентиль: 77%
0.01011
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

CVSS3: 5.3
nvd
больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

CVSS3: 5.3
github
больше 3 лет назад

Pion/DTLS contains buffer for inbound DTLS fragments with no limit

EPSS

Процентиль: 77%
0.01011
Низкий