PT-2024-31600 · Quicly · Quicly

Quictester

·

Published

2024-10-11

·

Updated

2024-11-12

·

CVE-2024-45396

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Quicly versions up to commtit d720707
Description: Quicly is an IETF QUIC protocol implementation. It is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes the process using quicly.
Recommendations: For Quicly versions up to commtit d720707, update to a version that includes commit 2a95896104901589c495bc41460262e64ffcad5c to address the vulnerability. As a temporary workaround, consider implementing measures to prevent remote attackers from triggering assertion failures, such as restricting access to the quicly process or monitoring for suspicious activity.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

CVE-2024-45396
GHSA-MP3C-H5GG-MM6P

Affected Products

Quicly