blob: 7042c48074b4e5262fbb033f22405e4919f1be66 [file] [log] [blame]
modules:
- module: github.com/pion/dtls/v2
versions:
- fixed: 2.2.4
vulnerable_at: 2.2.3
packages:
- package: github.com/pion/dtls/v2/pkg/protocol/handshake
symbols:
- MessageServerHello.Unmarshal
derived_symbols:
- Handshake.Unmarshal
summary: 'TODO(https://go.dev/issue/56443): fill in summary field'
description: |
Unmarshalling a Server Hello can panic, which
could allow a denial of service.
ghsas:
- GHSA-hxp2-xqf3-v83h
references:
- fix: https://github.com/pion/dtls/commit/7a14903448b70069fd9e02adf210ca23083c56d2