GHSA-hf3r-vmrv-7w29

Suggest an improvement
Source
https://github.com/advisories/GHSA-hf3r-vmrv-7w29
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hf3r-vmrv-7w29
Withdrawn
2024-01-03T21:06:15Z
Published
2024-01-03T18:30:51Z
Modified
2024-12-04T05:41:48Z
Summary
Duplicate Advisory: Denial of service in CBOR library
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6r92-cgxc-r5fg. This link is maintained to preserve external references.

Original Description

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in PeterO.Cbor. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

Database specific
{
    "cwe_ids":  [
        "CWE-407"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-01-03T21:06:15Z",
    "nvd_published_at":  "2024-01-03T16:15:09Z",
    "severity":  "HIGH"
}
References

Affected packages

NuGet / PeterO.Cbor

Package

Name
PeterO.Cbor
View open source insights on deps.dev
Purl
pkg:nuget/PeterO.Cbor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.5.1

Affected versions

4.*
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.0
4.4.0
4.4.1
4.4.2
4.4.4
4.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-hf3r-vmrv-7w29/GHSA-hf3r-vmrv-7w29.json"