Description
erlang-jose vulnerable to denial of service via large p2c value
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | | 1.11.10-1 |
 debian 14 | | | 1.11.10-1 |
 debian 11 | | =1.11.1-3 || =1.11.10-1 || =1.11.10-1~bpo12+1 || =1.11.12-1 || =1.11.12-1.1 || =1.11.2-1 || =1.11.2-1~bpo11+1 || =1.11.2-2 || =1.11.2-2~bpo11+1 || =1.11.5-1 || =1.11.5-1~bpo11+1 || =1.11.6-1 || =1.11.6-1~bpo12+1 | - |
 debian 12 | | =1.11.10-1 || =1.11.10-1~bpo12+1 || =1.11.12-1 || =1.11.12-1.1 || =1.11.5-1 || =1.11.6-1 || =1.11.6-1~bpo12+1 | - |
 hex | | =1.0.0 || =1.0.1 || =1.1.0 || =1.1.1 || =1.1.2 || =1.1.3 || =1.10.0 || =1.10.1 || =1.11.0 || =1.11.1 || =1.11.2 || =1.11.4 || =1.11.5 || =1.11.6 || =1.2.0 || =1.3.0 || =1.4.0 || =1.4.1 || =1.4.2 || =1.5.0 || =1.5.1 || =1.5.2 || =1.6.0 || =1.6.1 || =1.7.0 || =1.7.1 || =1.7.2 || =1.7.3 || =1.7.4 || =1.7.5 || =1.7.6 || =1.7.7 || =1.7.8 || =1.7.9 || =1.8.0 || =1.8.1 || =1.8.2 || =1.8.3 || =1.8.4 || =1.9.0 || >=0 <1.11.7 | 1.11.7 |