This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
SSL:FACEBOOK-FIZZ-TLS13-IO-DOS
|
Severity |
Major
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
SSL
|
Keywords |
Facebook Fizz TLS 1.3 Early Data Integer Overflow Denial of Service
|
Release Date |
2019/06/04
|
Update Number |
3177
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
SSL: Facebook Fizz TLS 1.3 Early Data Integer Overflow Denial of Service
This signature detects attempts to exploit a known vulnerability against Facebook Fizz. A successful attack can result in a denial-of-service condition.
Extended Description
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
Affected Products
- Facebook fizz 2018.09.24.00
- Facebook fizz 2018.10.01.00
- Facebook fizz 2018.10.08.00
- Facebook fizz 2018.10.15.00
- Facebook fizz 2018.10.22.00
- Facebook fizz 2018.10.29.00
- Facebook fizz 2018.11.05.00
- Facebook fizz 2018.11.12.00
- Facebook fizz 2018.11.19.00
- Facebook fizz 2018.11.26.00
- Facebook fizz 2018.12.03.00
- Facebook fizz 2018.12.10.00
- Facebook fizz 2018.12.17.00
- Facebook fizz 2018.12.24.00
- Facebook fizz 2018.12.31.00
- Facebook fizz 2019.01.07.00
- Facebook fizz 2019.01.14.00
- Facebook fizz 2019.01.21.00
- Facebook fizz 2019.01.28.00
- Facebook fizz 2019.02.04.00
- Facebook fizz 2019.02.11.00
- Facebook fizz 2019.02.18.00
- Facebook fizz 2019.02.25.00
References