quicly是H2O开源的一个 IETF QUIC 协议的实现。 quicly存在安全漏洞,该漏洞源于容易受到拒绝服务攻击,远程攻击者可以利用该漏洞触发断言失败,从而导致进程崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-45402 | 8.6 HIGH | Picotls double free |
| CVE-2024-45397 | 5.9 MEDIUM | H2O alllows bypassing address-based access control with 0-RTT |
| CVE-2024-45403 | 3.7 LOW | H2O assertion failure when HTTP/3 requests are cancelled |
| CVE-2024-25622 | 3.1 LOW | H2O ignores headers configuration directives |
No comments yet