CVE-2021-42143

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHello handshake message with an odd length of cipher suites, which triggers an infinite loop (consuming all resources) and a buffer over-read that can disclose sensitive information.
References
Link Resource
https://seclists.org/fulldisclosure/2024/Jan/16 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:contiki-ng:tinydtls:*:*:*:*:*:*:*:*

History

31 Jan 2024, 20:05

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Contiki-NG tinyDTLS a través de la rama maestra 53a0d97. Existe un error de bucle infinito durante el manejo de un mensaje de protocolo de enlace ClientHello. Este error permite a atacantes remotos provocar una denegación de servicio enviando un mensaje de protocolo de enlace ClientHello mal formado con una longitud impar de conjuntos de cifrado, lo que desencadena un bucle infinito (consumiendo todos los recursos) y una sobrelectura del búfer que puede revelar información confidencial.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Contiki-ng tinydtls
Contiki-ng
CWE CWE-835
References () https://seclists.org/fulldisclosure/2024/Jan/16 - () https://seclists.org/fulldisclosure/2024/Jan/16 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:contiki-ng:tinydtls:*:*:*:*:*:*:*:*

24 Jan 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 18:15

Updated : 2024-01-31 20:05


NVD link : CVE-2021-42143

Mitre link : CVE-2021-42143

CVE.ORG link : CVE-2021-42143


JSON object : View

Products Affected

contiki-ng

  • tinydtls
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')