OSV-2024-538

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/trafficserver/OSV-2024-538.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-538
Published
2024-06-06T00:12:59.950768Z
Modified
2024-07-16T14:22:07.747083Z
Summary
Use-of-uninitialized-value in QUICVariableInt::size
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=69001

Crash type: Use-of-uninitialized-value
Crash state:
QUICVariableInt::size
Http3SettingsFrame::Http3SettingsFrame
Http3FrameFactory::create
References

Affected packages

OSS-Fuzz / trafficserver

Package

Name
trafficserver
Purl
pkg:generic/trafficserver

Affected ranges

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "introduced_range": "9012706b4d4566b03e2bc4f02fb2ff5c8a4048c1:1c37f7ab7efc9ab521360654cacf3aacc5fdddc0",
    "fixed_range": "cb6dd9f3ed12f7efc345734825edd312d2aa1072:19b332ecf0bb17b96ec6435b537a736e1bb1c243"
}