There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-01-21T20:49:35.562Z
Reserved: 2023-01-17T19:56:08.425Z
Link: CVE-2023-23759

Updated: 2024-08-02T10:42:25.872Z

Status : Modified
Published: 2023-05-18T22:15:09.597
Modified: 2025-01-21T21:15:08.963
Link: CVE-2023-23759

No data.