CVE-2019-11924
20.08.2019, 20:15
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.Enginsight
Vendor | Product | Version |
---|---|---|
fizz | 2019.01.28.00 ≤ 𝑥 ≤ 2019.08.05.00 |
𝑥
= Vulnerable software versions
References