x/vulndb: potential Go vuln in github.com/cloudflare/goflow: CVE-2022-2529 #1032
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-2529 references github.com/cloudflare/goflow, which may be a Go module.
Description:
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to consume large amounts of memory resulting in a denial of service.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: