The package github.com/containrrr/shoutrrr/pkg/util before 0.6.0 are vulnerable to Denial of Service (DoS) via the util.PartitionMessage function. Exploiting this vulnerability is possible by sending exactly 2000, 4000, or 6000 characters messages.
References
Link | Resource |
---|---|
https://github.com/containrrr/shoutrrr/commit/6a27056f9d7522a8b493216195cb7634bf4b5c42 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/issues/240 | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/pull/242 | Patch Third Party Advisory |
https://github.com/containrrr/shoutrrr/releases/tag/v0.6.0 | Release Notes Third Party Advisory |
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINRRRSHOUTRRRPKGUTIL-2849059 | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: snyk
Published: 2022-07-15T00:00:00
Updated: 2022-07-15T20:01:13
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-25891
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-15T20:15:08.540
Modified: 2022-07-21T14:35:24.517
Link: CVE-2022-25891
JSON object: View
Redhat Information
No data.
CWE