CVE Vulnerabilities

CVE-2023-43669

Published: Sep 21, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).

Affected Software

Name Vendor Start Version End Version
Tungstenite Snapview * 0.20.0 (including)
Rust-tungstenite Ubuntu bionic *
Rust-tungstenite Ubuntu mantic *
Rust-tungstenite Ubuntu trusty *
Rust-tungstenite Ubuntu xenial *

References