GHSA-xh5m-8qqp-c5x7
Dashboard / Vulnerabilities / GHSA-xh5m-8qqp-c5x7
GHSA-xh5m-8qqp-c5x7
Summary: Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
Details: ### Impact The MsQuic server application or process will crash, resulting in a denial of service. ### Patches The following patch was made: - Don't Allow Version Negotiation Packets for Server Connections - https://github.com/microsoft/msquic/commit/3226cff07d22662f16fc98d605656860e64cd343 ### Workarounds Beyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality.
References: https://github.com/microsoft/msquic/security/advisories/GHSA-xh5m-8qqp-c5x7, https://nvd.nist.gov/vuln/detail/CVE-2023-38171, https://github.com/microsoft/msquic/commit/3226cff07d22662f16fc98d605656860e64cd343, https://github.com/microsoft/msquic, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38171
Affected packages
Package
Name: Microsoft.Native.Quic.MsQuic.Schannel
Purl: pkg:nuget/Microsoft.Native.Quic.MsQuic.Schannel
Affected ranges
Type: ECOSYSTEM
Events:
