AWSGHSA-gj4j-vp5f-86cf
Potential denial of service when sending version negotiation or close packets
MediumPublished May 5, 2022
Some sender components could potentially panic when writing packets, leading to the endpoint shutting down. AWS Services are not affected by this issue. Customers using `s2n-quic` in their applications should update to the most recent version. All versions of `s2n-quic` before and including v1.1.0 are affected by this issue. Customers should upgrade to v1.1.1. Note that this issue does not affect `s2n-tls`.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-quic crates.io | < v1.1.1 | v1.1.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 102022 | Privilege Escalation Vector in CloudWatch Agent for Windows | High7.1 | 1.247355 |
| Sep 272022 | Issue with configuring session ticket names in s2n-tls | Medium | v1.3.23 |
| Sep 272022 | Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake | Low | <v1.3.23 |
| Aug 92022 | Partial Path Traversal in aws-cpp-sdk-transfer | Medium | v1.9.318 |
| Jul 152022 | Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 | High7.9 | 1.12.261 |
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |