CVE-2018-6343

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.
Configurations

Configuration 1

cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:*

Information

Published : 2018-12-31 10:29

Updated : 2019-10-09 11:41


NVD link : CVE-2018-6343

Mitre link : CVE-2018-6343

Products Affected
No products.
CWE