Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2x3r-3grm-f4ww

Опубликовано: 19 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

EPSS

Процентиль: 43%
0.0021
Низкий

7.5 High

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

EPSS

Процентиль: 43%
0.0021
Низкий

7.5 High

CVSS3

Дефекты

CWE-617