Описание
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
Ссылки
- Patch
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2023.01.30.00 (исключая)
cpe:2.3:a:facebook:fizz:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.0021
Низкий
7.5 High
CVSS3
Дефекты
CWE-617
CWE-617
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
EPSS
Процентиль: 43%
0.0021
Низкий
7.5 High
CVSS3
Дефекты
CWE-617
CWE-617