CVE-2022-29189 Information

Description

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4 a buffer that was used for inbound network traffic had no upper limit. Pion DTLS would buffer all network traffic from the remote user until the handshake completes or timed out. An attacker could exploit this to cause excessive memory usage. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Reference

https://github.com/pion/dtls/commit/a6397ff7282bc56dc37a68ea9211702edb4de1de https://github.com/pion/dtls/security/advisories/GHSA-cx94-mrg9-rq4j https://github.com/pion/dtls/releases/tag/v2.1.4

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

5.3

Share on: