An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of service.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://github.com/contiki-ng/tinydtls/issues/27 | patch |
http://packetstormsecurity.com/files/176625/Contiki-NG-tinyDTLS-Denial-Of-Service.html | third party advisory vdb entry |
https://seclists.org/fulldisclosure/2024/Jan/14 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2024/Jan/14 |