CVE-2023-43669
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
El Tungstenite crate anterior a la versión 0.20.1 para Rust permite a atacantes remotos provocar una denegación del servicio (de minutos de consumo de la CPU) a través de una longitud excesiva de un encabezado HTTP en el handshake del cliente. La longitud afecta tanto a cuántas veces se intenta un análisis (por ejemplo, miles de veces) y la cantidad promedio de datos para cada intento de análisis (por ejemplo, millones de bytes).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-21 CVE Reserved
- 2023-09-21 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-10-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2240110 | Issue Tracking | |
https://bugzilla.suse.com/show_bug.cgi?id=1215563 | Issue Tracking | |
https://crates.io/crates/tungstenite/versions | Release Notes | |
https://cwe.mitre.org/data/definitions/407.html | Technical Description | |
https://github.com/advisories/GHSA-9mcr-873m-xcxp | Third Party Advisory | |
https://security-tracker.debian.org/tracker/CVE-2023-43669 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/snapview/tungstenite-rs/issues/376 | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://github.com/github/advisory-database/pull/2752 | 2024-02-16 | |
https://github.com/snapview/tungstenite-rs/commit/8b3ecd3cc0008145ab4bc8d0657c39d09db8c7e2 | 2024-02-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Snapview Search vendor "Snapview" | Tungstenite Search vendor "Snapview" for product "Tungstenite" | <= 0.20.0 Search vendor "Snapview" for product "Tungstenite" and version " <= 0.20.0" | rust |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 39 Search vendor "Fedoraproject" for product "Fedora" and version "39" | - |
Affected
|