Back to search
CVE-2015-2313
Published: Aug 9, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which triggers a "tight" for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150317 Re: CVE Request: Cap'n Proto: Several issues
mailing-list
x_refsource_MLIST
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780568
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now