Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
0.23.13 (semver) before 0.23.18
affected
Default status
unaffected
Default status
unaffected
Description
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
Problem types
Product status
0.23.13 (semver) before 0.23.18
Timeline
| 2024-11-25: | Reported to Red Hat. |
| 2024-11-25: | Made public. |
References
access.redhat.com/security/cve/CVE-2024-11738
bugzilla.redhat.com/show_bug.cgi?id=2328732 (RHBZ#2328732)
github.com/advisories/GHSA-qg5g-gv98-5ffh
github.com/rustls/rustls/issues/2227
rustsec.org/advisories/RUSTSEC-2024-0399.html