Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-892h-r6cr-53g4

Опубликовано: 08 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
redhat
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
nvd
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
debian
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffe ...

oracle-oval
больше 1 года назад

ELSA-2023-7763: runc security update (MODERATE)

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770