Vulnerabilities > CVE-2020-24944 - Infinite Loop vulnerability in Privateoctopus Picoquic

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
privateoctopus
CWE-835

Summary

picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_decode_frames and picoquic_decode_stream_frame functions and epoch==3.

Vulnerable Configurations

Part Description Count
Application
Privateoctopus
1