CVE-2024-23684

Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause a denial of service by passing a maliciously crafted input. Depending on an application's use of this library, this may be a remote attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:peteroupc:cbor:*:*:*:*:*:.net:*:*

History

26 Jan 2024, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:peteroupc:cbor:*:*:*:*:*:.net:*:*
First Time Peteroupc cbor
Peteroupc
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) La complejidad algorítmica ineficiente en la función DecodeFromBytes en com.upokecenter.cbor la implementación Java de Concise Binary Object Representation (CBOR) versiones 4.0.0 a 4.5.1 permite a un atacante provocar una denegación de servicio al pasar una entrada manipulada con fines malintencionados. Dependiendo del uso de esta librería por parte de una aplicación, este puede ser un atacante remoto.
References () https://github.com/advisories/GHSA-fj2w-wfgv-mwq6 - () https://github.com/advisories/GHSA-fj2w-wfgv-mwq6 - Mitigation, Third Party Advisory
References () https://github.com/peteroupc/CBOR-Java/security/advisories/GHSA-fj2w-wfgv-mwq6 - () https://github.com/peteroupc/CBOR-Java/security/advisories/GHSA-fj2w-wfgv-mwq6 - Vendor Advisory
References () https://vulncheck.com/advisories/vc-advisory-GHSA-fj2w-wfgv-mwq6 - () https://vulncheck.com/advisories/vc-advisory-GHSA-fj2w-wfgv-mwq6 - Third Party Advisory

19 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 21:15

Updated : 2024-01-26 18:06


NVD link : CVE-2024-23684

Mitre link : CVE-2024-23684

CVE.ORG link : CVE-2024-23684


JSON object : View

Products Affected

peteroupc

  • cbor
CWE
CWE-407

Inefficient Algorithmic Complexity