Ubuntu Security Update USN-8300-1: ngtcp2 vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,771
Reaction score
74
Credits
-1,257
Zou Dikai discovered that ngtcp2 serialized peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog was enabled, a remote attacker could possibly use this issue to execute arbitrary code.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top