CVE-2023-23759
HIGHFacebook Fizz < 2023.01.30.00 - Denial of Service via ClientHello Cipher Advertisement Change
Title source: llmDescription
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.facebook.com/security/advisories/cve-2023-23759
Scores
CVSS v3
7.5
EPSS
0.0072
EPSS Percentile
49.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-617
Status
published
Products (1)
facebook/fizz
< 2023.01.30.00
Published
May 18, 2023
Tracked Since
Feb 18, 2026