UBUNTU-CVE-2022-30591
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-30591
UBUNTU-CVE-2022-30591
Summary:
Details: ** DISPUTED ** quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List.
References: https://ubuntu.com/security/CVE-2022-30591, https://github.com/lucas-clemente/quic-go/blob/84e03e59760ceee37359688871bb0688fcc4e98f/mtu_discoverer.go, https://www.cve.org/CVERecord?id=CVE-2022-30591
Affected packages
Package
Name: golang-github-lucas-clemente-quic-go
Purl: pkg:deb/ubuntu/golang-github-lucas-clemente-quic-go
Affected ranges
Type: ECOSYSTEM
Events:
