Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processing. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds available.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dtls | Pion | * | 2.1.4 (excluding) |
Pion | Ubuntu | bionic | * |
Snowflake | Ubuntu | kinetic | * |
Snowflake | Ubuntu | lunar | * |
Snowflake | Ubuntu | mantic | * |
Telegraf | Ubuntu | impish | * |
Telegraf | Ubuntu | kinetic | * |
Telegraf | Ubuntu | lunar | * |
Telegraf | Ubuntu | mantic | * |