跳转到帖子

FreeBSD: VID-71F3E9F0-BAFC-11EF-885D-901B0E934D69 (CVE-2024-52805): py-matrix-synapse -- multiple vulnerabilities in versions prior to 1.120.1

recommended_posts

发布于
  • Members

FreeBSD: VID-71F3E9F0-BAFC-11EF-885D-901B0E934D69 (CVE-2024-52805): py-matrix-synapse -- multiple vulnerabilities in versions prior to 1.120.1

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
12/03/2024
Created
12/19/2024
Added
12/18/2024
Modified
12/18/2024

Description

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.

Solution(s)

  • freebsd-upgrade-package-py310-matrix-synapse
  • freebsd-upgrade-package-py311-matrix-synapse
  • freebsd-upgrade-package-py38-matrix-synapse
  • freebsd-upgrade-package-py39-matrix-synapse

References

  • CVE-2024-52805
  • 查看数 697
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…