There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: facebook
Published: 2023-05-18T21:21:02.735Z
Updated: 2024-08-02T10:42:25.872Z
Reserved: 2023-01-17T19:56:08.425Z
Link: CVE-2023-23759
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-18T22:15:09.597
Modified: 2024-11-21T07:46:46.670
Link: CVE-2023-23759
Redhat
No data.