CVE-2020-5234

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:*:*:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.94:alpha:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.110:alpha:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.119:beta:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.123:beta:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.204:beta:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.270:rc:*:*:*:c\#:*:*
cpe:2.3:a:messagepack:messagepack:2.0.299:rc:*:*:*:c\#:*:*

History

No history.

Information

Published : 2020-01-31 18:15

Updated : 2024-11-21 05:33


NVD link : CVE-2020-5234

Mitre link : CVE-2020-5234

CVE.ORG link : CVE-2020-5234


JSON object : View

Products Affected

messagepack

  • messagepack
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write