/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-rq7w-438m-4vjp

Published

Last updated

https://images.chainguard.dev/security/CGA-rq7w-438m-4vjp
Package

pgcat

Latest Update
Fixed
Fixed Version

1.2.0-r1

Aliases
  • GHSA-fh2r-99q2-6mmg

Severity

7.5

High

CVSS V3

Summary

rustls-webpki: CPU denial of service in certificate path building

Description

When this crate is given a pathological certificate chain to validate, it will spend CPU time exponential with the number of candidate certificates at each step of path building.

Both TLS clients and TLS servers that accept client certificate are affected.

We now give each path building operation a budget of 100 signature verifications.

The original webpki crate is also affected, see GHSA-8qv2-5vq6-g2g7.

This was previously reported in the original crate https://github.com/briansmith/webpki/issues/69 and re-reported to us recently.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images