There is a vulnerability in the fizz library prior to...
High severity
Unreviewed
Published
May 19, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 18, 2023
Published to the GitHub Advisory Database
May 19, 2023
Last updated
Apr 4, 2024
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
References