Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0048 | Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory. |
Github GHSA |
GHSA-gfvq-mxw3-mfq3 | asyncua vulnerable to denial of service via infinite loop |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-20T14:16:00.651Z
Reserved: 2023-02-20T10:28:48.929Z
Link: CVE-2023-26151
Updated: 2024-08-02T11:39:06.637Z
Status : Modified
Published: 2023-10-03T05:15:50.507
Modified: 2024-11-21T07:50:53.170
Link: CVE-2023-26151
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA