NA

CVE-2023-42805

Published: 21/09/2023 Updated: 25/09/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases.

Vulnerable Product Search on Vulmon Subscribe to Product

quinn project quinn

Vendor Advisories

Debian Bug report logs - #1052546 rust-quinn-proto: CVE-2023-42805 Package: src:rust-quinn-proto; Maintainer for src:rust-quinn-proto is Debian Rust Maintainers <pkg-rust-maintainers@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 Sep 2023 11:48:02 UTC Severity: important ...

Github Repositories

QUICTester Total faults found: 55 (3 CVEs assigned) 44 specification violations (An implemented behavior violates the QUIC specification) 8 memory-related bugs (An input causing a memory corruption and a server crash) 3 logic flaws (Incorrect logic implemented in code produces unexpected behavior) CVEs CVE-2023-42805 CVE-2024-25679 CVE-2024-25678 Faults that are resolved