CVE-2023-3766: odoh-rs's Invalid Slice Split Results in Server Panic
(updated )
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients.
References
- github.com/advisories/GHSA-gpcv-p28p-fv2p
- github.com/cloudflare/odoh-rs
- github.com/cloudflare/odoh-rs/commit/c1bc4ed71dcc9842b7dc1ea26f278f105074bbaa
- github.com/cloudflare/odoh-rs/pull/28
- github.com/cloudflare/odoh-rs/security/advisories/GHSA-gpcv-p28p-fv2p
- nvd.nist.gov/vuln/detail/CVE-2023-3766
- rustsec.org/advisories/RUSTSEC-2023-0095.html
Code Behaviors & Features
Detect and mitigate CVE-2023-3766 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →