--- vuln.xml Fri Jul 3 09:57:24 2020 +++ vuln.xml Fri Jul 3 10:55:22 2020 @@ -60,0 +61,42 @@ + + envoy -- multiple vulnerabilities + + + istio + 1.5.01.5.6 + + + envoy + 1.12.5 + + + + +

istio developers report:

+
+

Envoy, and subsequently Istio, are vulnerable to four newly discovered vulnerabilities

+
    +
  • CVE-2020-12603: By sending a specially crafted packet, an attacker could cause Envoy to consume excessive amounts of memory when proxying HTTP/2 requests or responses.
  • +
  • CVE-2020-12605: An attacker could cause Envoy to consume excessive amounts of memory when processing specially crafted HTTP/1.1 packets.
  • +
  • CVE-2020-8663: An attacker could cause Envoy to exhaust file descriptors when accepting too many connections.
  • +
  • CVE-2020-12604: An attacker could cause increased memory usage when processing specially crafted packets.
  • +
+
+ +
+ + https://github.com/envoyproxy/envoy/security/advisories/GHSA-pc38-4q6c-85p6 + https://github.com/envoyproxy/envoy/security/advisories/GHSA-8hf8-8gvw-ggvx + https://github.com/envoyproxy/envoy/security/advisories/GHSA-fjxc-jj43-f777 + https://github.com/envoyproxy/envoy/security/advisories/GHSA-v8q7-fq78-4997 + CVE-2020-8663 + CVE-2020-12605 + CVE-2020-12604 + CVE-2020-12603 + + + 2020-06-30 + 2020-07-03 + +
+