The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"284809006286680919427161787392807523022",
"129043644459132106917369119903605255834",
"183095706840729272751797894355802956212",
"333577374693175214850873859112633988887"
]
},
"id": "CVE-2018-25021-61a6fc34",
"source": "https://github.com/toktok/c-toxcore/commit/3f35a84968f100e1e6d3c9df467fd3c82a9ebb13",
"signature_type": "Line",
"target": {
"file": "toxcore/tox.api.h"
},
"signature_version": "v1",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-25021.json"