Cap'n Proto 'layout.c++' Denial of Service Vulnerability
BID:73128
Info
Cap'n Proto 'layout.c++' Denial of Service Vulnerability
| Bugtraq ID: | 73128 |
| Class: | Design Error |
| CVE: |
CVE-2015-2313 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2015 12:00AM |
| Updated: | Mar 05 2015 12:00AM |
| Credit: | David Renshaw |
| Vulnerable: |
Sandstorm.io Cap'n Proto 0.4.1 Sandstorm.io Cap'n Proto 0.5.1.1 |
| Not Vulnerable: |
Sandstorm.io Cap'n Proto 0.5.1.2 Sandstorm.io Cap'n Proto 0.4.1.1 |
Exploit / POC
Cap'n Proto 'layout.c++' Denial of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Cap'n Proto 'layout.c++' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cap'n Proto 'layout.c++' Denial of Service Vulnerability
References:
References:
- 2015-03-05-0-c++-addl-cpu-amplification.md (capnproto)
- Cap�??n Proto Home Page (capnproto)
- CPU usage amplification attack #2 (Tom Lee)