Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29189

Опубликовано: 21 мая 2022
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pion:dtls:*:*:*:*:*:*:*:*
Версия до 2.1.4 (исключая)

EPSS

Процентиль: 77%
0.01011
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

CVSS3: 5.3
debian
больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. ...

CVSS3: 5.3
github
больше 3 лет назад

Pion/DTLS contains buffer for inbound DTLS fragments with no limit

EPSS

Процентиль: 77%
0.01011
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-120