Résumé

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Détails de l’avis

Impact

Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.

Patches

Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.

Workarounds

No work around; please upgrade to v3.1.4 or a newer version.

Références