RUSTSEC-2023-0065
Dashboard / Vulnerabilities / RUSTSEC-2023-0065
RUSTSEC-2023-0065
Published: 25 Sept 2023Last Modified: 8 Nov 2023
Aliases:
Summary: Tungstenite allows remote attackers to cause a denial of service
Details: The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
References: https://crates.io/crates/tungstenite, https://rustsec.org/advisories/RUSTSEC-2023-0065.html, https://github.com/snapview/tungstenite-rs/issues/376
Affected packages
Package
Name: tungstenite
Purl: pkg:cargo/tungstenite
Affected ranges
Type: SEMVER
Events:
Introduced- 0.0.0-0
Fixed -0.20.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
