Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-43669
HistorySep 21, 2023 - 12:00 a.m.

CVE-2023-43669

2023-09-2100:00:00
ubuntu.com
ubuntu.com
5
tungstenite crate
denial of service
rust
http header length

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

70.8%

The Tungstenite crate before 0.20.1 for Rust allows remote attackers to
cause a denial of service (minutes of CPU consumption) via an excessive
length of an HTTP header in a client handshake. The length affects both how
many times a parse is attempted (e.g., thousands of times) and the average
amount of data for each parse attempt (e.g., millions of bytes).

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu23.10noarchrust-tungstenite< anyUNKNOWN
ubuntu24.04noarchrust-tungstenite< anyUNKNOWN

References

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

70.8%