Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-39322

Опубликовано: 08 сент. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия от 1.21.0 (включая) до 1.21.1 (исключая)

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
redhat
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
debian
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffe ...

CVSS3: 7.5
github
почти 2 года назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

oracle-oval
больше 1 года назад

ELSA-2023-7763: runc security update (MODERATE)

EPSS

Процентиль: 12%
0.00041
Низкий

7.5 High

CVSS3

Дефекты

CWE-770