CVE-2024-21909

high

Description

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in PeterO.Cbor. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

References

https://vulncheck.com/advisories/vc-advisory-GHSA-6r92-cgxc-r5fg

https://github.com/peteroupc/CBOR/security/advisories/GHSA-6r92-cgxc-r5fg

https://github.com/peteroupc/CBOR/compare/v4.5...v4.5.1

https://github.com/peteroupc/CBOR/commit/b4117dbbb4cd5a4a963f9d0c9aa132f033e15b95

https://github.com/advisories/GHSA-6r92-cgxc-r5fg

Details

Source: Mitre, NVD

Published: 2024-01-03

Updated: 2024-02-08

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High