← Back to CVE List

CVE-2017-17066

Published: 2017-12-05T09:29Z
Last Modified: 2024-11-21T03:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading sensitive router memory, aka the GarlicRust bug. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt