The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).
[ { "source": "https://github.com/toktok/c-toxcore/commit/3f35a84968f100e1e6d3c9df467fd3c82a9ebb13", "signature_version": "v1", "target": { "file": "toxcore/tox.api.h" }, "digest": { "line_hashes": [ "284809006286680919427161787392807523022", "129043644459132106917369119903605255834", "183095706840729272751797894355802956212", "333577374693175214850873859112633988887" ], "threshold": 0.9 }, "deprecated": false, "signature_type": "Line", "id": "CVE-2018-25021-61a6fc34" } ]