Vulnerability Description
Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Envoyproxy | Envoy | < 1.16.1 |
References
- https://github.com/envoyproxy/envoy/compare/v1.16.0...v1.16.1PatchThird Party Advisory
- https://github.com/envoyproxy/envoy/issues/14113ExploitThird Party Advisory
- https://github.com/envoyproxy/envoy/pull/14122PatchThird Party Advisory
- https://github.com/envoyproxy/envoy/compare/v1.16.0...v1.16.1PatchThird Party Advisory
- https://github.com/envoyproxy/envoy/issues/14113ExploitThird Party Advisory
- https://github.com/envoyproxy/envoy/pull/14122PatchThird Party Advisory
FAQ
What is CVE-2020-35471?
CVE-2020-35471 is a vulnerability with a CVSS score of 7.5 (HIGH). Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.
How severe is CVE-2020-35471?
CVE-2020-35471 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35471?
Check the references section above for vendor advisories and patch information. Affected products include: Envoyproxy Envoy.