GHSA-fr44-546p-7xcp
Dashboard / Vulnerabilities / GHSA-fr44-546p-7xcp
GHSA-fr44-546p-7xcp
Summary: MsQuic Remote Denial of Service Vulnerability
Details: ### Impact The MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. ### Patches The following patch was made: - Fix Memory Leak from Multiple Decodes of TP - https://github.com/microsoft/msquic/commit/d364feeda0dd8b729eca6fef149c1ef98630f0cb ### Workarounds Beyond upgrading to the patched versions, there is no other workaround.
References: https://github.com/microsoft/msquic/security/advisories/GHSA-fr44-546p-7xcp, https://nvd.nist.gov/vuln/detail/CVE-2023-36435, https://github.com/microsoft/msquic/commit/d364feeda0dd8b729eca6fef149c1ef98630f0cb, https://github.com/microsoft/msquic, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36435
Affected packages
Package
Name: Microsoft.Native.Quic.MsQuic.OpenSSL
Purl: pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL
Affected ranges
Type: ECOSYSTEM
Events:
