GHSA-5xc6-fpc7-4qvg
Dashboard / Vulnerabilities / GHSA-5xc6-fpc7-4qvg
GHSA-5xc6-fpc7-4qvg
Summary: CoAPthon DoS due to Exceptions
Details: The `Serialize.deserialize()` method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a denial of service in applications that use this library (e.g., the standard CoAP server, CoAP client, CoAP reverse proxy, example collect CoAP server and client) when they receive crafted CoAP messages.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-12680, https://github.com/Tanganelli/CoAPthon/issues/135, https://github.com/Tanganelli/CoAPthon, https://github.com/advisories/GHSA-5xc6-fpc7-4qvg, https://github.com/pypa/advisory-database/tree/main/vulns/coapthon/PYSEC-2019-165.yaml
Affected packages
Package
Name: coapthon
Purl: pkg:pypi/coapthon
Affected ranges
Type: ECOSYSTEM
Events:
