cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by sending a long enough object. Version 5.6.2 contains a patch for this issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-19 23:15
Updated : 2024-04-19 23:15
NVD link : CVE-2024-26134
Mitre link : CVE-2024-26134
CVE.ORG link : CVE-2024-26134
JSON object : View
Products Affected
No product.
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')