Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j222-r86r-wpv4

Опубликовано: 20 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-787