Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Excessive memory allocation in s2n-quic
Vulnerability Description
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.
To remediate this issue, users should upgrade to v1.8.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
s2n-quic 安全漏洞
Vulnerability Description
s2n-quic是Amazon Web Services开源的一款高性能QUIC协议实现库。 s2n-quic 1.8.2之前版本存在安全漏洞,该漏洞源于CRYPTO帧重组器中无界内存分配,可能导致未经身份验证的远程攻击者通过发送特制QUIC Initial数据包造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A