A Denial of Service due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk. Reference: https://github.com/open62541/open62541/pull/5173 https://security.snyk.io/vuln/SNYK-UNMANAGED-OPEN62541OPEN62541-2988719 https://github.com/open62541/open62541/releases/tag/v1.2.5 https://github.com/open62541/open62541/commit/b79db1ac78146fc06b0b8435773d3967de2d659c https://github.com/open62541/open62541/releases/tag/v1.3.1
Created open62541 tracking bugs for this issue: Affects: epel-7 [bug 2122902] Affects: fedora-all [bug 2122901]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.