NA

CVE-2023-50966

Published: 19/03/2024 Updated: 19/03/2024

Vulnerability Summary

erlang-jose (aka JOSE for Erlang and Elixir) up to and including 1.11.6 allow malicious users to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

Vendor Advisories

Debian Bug report logs - #1067456 erlang-jose: CVE-2023-50966 Package: src:erlang-jose; Maintainer for src:erlang-jose is Ejabberd Packaging Team <ejabberd@packagesdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 21 Mar 2024 19:27:01 UTC Severity: important Tags: security, upstream Forwar ...