PT-2019-12560 · Fizz · Fizz

Published

2019-08-20

·

Updated

2020-08-24

·

CVE-2019-11924

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions fizz versions v2019.01.28.00 through v2019.08.04.00
Description A peer could send empty handshake fragments containing only padding, which would be kept in memory until a full handshake was received, resulting in memory exhaustion.
Recommendations For versions v2019.01.28.00 through v2019.08.04.00, update to version v2019.08.05.00 or later to resolve the issue.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11924

Affected Products

Fizz