CVE-2015-2313 Information
Feb 14, 2021
cve
Description
Sandstorm Cap’n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2 when an application invokes the totalSize method on an object reader allows remote peers to cause a denial of service (CPU consumption) via a crafted small message which triggers a \tight\ for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://www.openwall.com/lists/oss-security/2015/03/17/3 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780568 https://github.com/capnproto/capnproto/blob/master/security-advisories/2015-03-05-0-c2B2B-addl-cpu-amplification.md https://github.com/capnproto/capnproto/commit/80149744bdafa3ad4eedc83f8ab675e27baee868
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: