cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Jan 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Agronholm
Agronholm cbor2 Fedoraproject Fedoraproject fedora |
|
CPEs | cpe:2.3:a:agronholm:cbor2:*:*:*:*:*:python:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
Vendors & Products |
Agronholm
Agronholm cbor2 Fedoraproject Fedoraproject fedora |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-02-19T22:13:47.173Z
Updated: 2024-08-14T13:57:54.799Z
Reserved: 2024-02-14T17:40:03.687Z
Link: CVE-2024-26134
Vulnrichment
Updated: 2024-08-01T23:59:32.554Z
NVD
Status : Analyzed
Published: 2024-02-19T23:15:07.810
Modified: 2025-01-02T14:18:48.553
Link: CVE-2024-26134
Redhat
No data.