Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39321

Опубликовано: 06 сент. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

A flaw was found in Golang. Processing an incomplete post-handshake message for a QUIC connection caused a panic.

Отчет

The flaw has been marked as moderate instead of high like NVD QUICConn.HandleData buffers data and passes it to handlePostHandshakeMessage every time the buffer contains a complete message, while HandleData doesn't limit the amount of data it can buffer, a panic or denial of service would likely be lower severity,also in order to exploit this vulnerability, an attacker would have to smuggle partial handshake data which might be rejected altogether as per tls RFC specification.Therfore because of a lower severity denial of service and conditions that are beyond the scope of attackers control,we have marked this as moderate severity

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-operator-rhel9Not affected
Cost Management Metrics Operatorcostmanagement/costmanagement-metrics-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Logical Volume Manager Storagelvms4/topolvm-rhel9Affected
mirror registry for Red Hat OpenShiftmirror-registry-containerWill not fix
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel8-operatorWill not fix
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorAffected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Pipelinesopenshift-pipelines-clientAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2237777golang: crypto/tls: panic when processing post-handshake message on QUIC connections

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVSS3: 7.5
nvd
около 2 лет назад

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVSS3: 7.5
debian
около 2 лет назад

Processing an incomplete post-handshake message for a QUIC connection ...

CVSS3: 7.5
github
около 2 лет назад

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость функции HandleData() пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 17%
0.00055
Низкий

7.5 High

CVSS3