RUSTSEC-2022-0084

    Dashboard / Vulnerabilities / RUSTSEC-2022-0084

    RUSTSEC-2022-0084

    Published: 12 Jul 2022Last Modified: 8 Nov 2023

    Summary: libp2p Lack of resource management DoS

    Details: libp2p allows a potential attacker to cause victim p2p node to run out of memory The out of memory failure can cause crashes where libp2p is intended to be used within large scale networks leading to potential Denial of Service (DoS) vector Users should upgrade or reference the [DoS mitigation strategies](https://docs.libp2p.io/reference/dos-mitigation/).

    Affected packages

    Package

    Name: libp2p

    Purl: pkg:cargo/libp2p

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -0.45.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2022-0084 | CVE-DB