GHSA-hxq4-mx37-fqvg

    Dashboard / Vulnerabilities / GHSA-hxq4-mx37-fqvg

    GHSA-hxq4-mx37-fqvg

    Published: 30 Jun 2023Last Modified: 30 Jun 2023

    Summary: s2n-quic potential denial of service vulnerability when receiving empty UDP packets

    Details: ### Impact An issue in s2n-quic results in the endpoint shutting down after receiving an empty UDP packet on a connection. No AWS services are affected by this issue and customers of AWS services do not need to take action. Applications using s2n-quic should upgrade their application to the most recent release of s2n-quic. Impacted version: s2n-quic v1.22.0. ### Patches The patch is included in s2n-quic [v1.23.0](https://github.com/aws/s2n-quic/releases/tag/v1.23.0). If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

    Affected packages

    Package

    Name: s2n-quic

    Purl: pkg:cargo/s2n-quic

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.22.0
    Fixed -1.23.0

    Affected versions

    1.22.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hxq4-mx37-fqvg | CVE-DB