VDB
Sign up
—

GO-2020-0038

Improper authentication in github.com/pion/dtls

Quick fix

GO-2020-0038 — github.com/pion/dtls: upgrade to the fixed version with the command below.

go get github.com/pion/dtls@v1.5.2

Details

Due to improper verification of packets, unencrypted packets containing application data are accepted after the initial handshake. This allows an attacker to inject arbitrary data which the client/server believes was encrypted, despite not knowing the session key.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/pion/dtls
Introduced in: 0Fixed in: 1.5.2
Fixgo get github.com/pion/dtls@v1.5.2

References