THREAT OPS › Threat News › [NVD] CVE-2023-39533 (HIGH 7.5) — go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability
[NVD] CVE-2023-39533 (HIGH 7.5) — go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability
CVE-2023-39533 CVSS: 7.5 HIGH Published: 2023-08-08T19:15:10.657
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability is present in the core/crypto module of go-libp2p and
Indicators of compromise
- CVE-2023-39533cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-39533