GHSA-frg3-gpcx-968f
Dashboard / Vulnerabilities / GHSA-frg3-gpcx-968f
Summary: SwiftNIO SSL arbitrary code execution vulnerability
Details: A SwiftNIO application using TLS may be able to execute arbitrary code. The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-8849, https://github.com/apple/swift-nio-ssl/commit/109faef770994e71b6bafcc015e2e96b88a4af8c, https://github.com/apple/swift-nio-ssl, https://github.com/apple/swift-nio-ssl/releases/tag/2.4.1, https://security.snyk.io/vuln/SNYK-COCOAPODS-SWIFTNIOSSL-8492737, https://support.apple.com/HT210772
Affected packages
Package
Name: github.com/apple/swift-nio-ssl
Purl: pkg:swift/github.com/apple/swift-nio-ssl
Affected ranges
Type: SEMVER
Events:
