Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47609

Опубликовано: 01 окт. 2024
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

A flaw was found in the hyperium/tonic package. In certain conditions, it may be possible for a remote attacker to cause the application to terminate upon accepting a TCP/TLS stream, which may lead to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-755
https://bugzilla.redhat.com/show_bug.cgi?id=2316017rust-tonic: Remotely exploitable DoS in Tonic `<=v0.12.2`

EPSS

Процентиль: 47%
0.00241
Низкий

3.7 Low

CVSS3

Связанные уязвимости

ubuntu
больше 1 года назад

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

nvd
больше 1 года назад

Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out with errors that were not covered correctly causing the accept loop to exit. Upgrading to tonic 0.12.3 and above contains the fix.

debian
больше 1 года назад

Tonic is a native gRPC client & server implementation with async/await ...

CVSS3: 5.3
github
больше 1 года назад

Tonic has remotely exploitable denial of service vulnerability

EPSS

Процентиль: 47%
0.00241
Низкий

3.7 Low

CVSS3