Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfvq-mxw3-mfq3

Опубликовано: 03 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

asyncua vulnerable to denial of service via infinite loop

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

Пакеты

Наименование

asyncua

pip
Затронутые версииВерсия исправления

< 0.9.96

0.9.96

EPSS

Процентиль: 35%
0.00148
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

CVSS3: 5.3
nvd
больше 2 лет назад

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

EPSS

Процентиль: 35%
0.00148
Низкий

7.5 High

CVSS3

Дефекты

CWE-835