ixray-team ixray-1.6-stcop Infinite Loop Vulnerability
Vulnerability
A vulnerability causing an infinite loop has been identified in ixray-team ixray-1.6-stcop, prior to version 1.3. This issue arises in the 'src/3rd-party/crypto/openssl/src/bn_sqrt.c' file, which was cloned from the OpenSSL project but did not incorporate a critical security patch. The original vulnerability, related to improper handling of certain calculations, was addressed in the OpenSSL repository under CVE-2022-0778.
Impact
Exploitation of this vulnerability leads to an infinite loop, causing the application to become unresponsive and potentially available resources to be exhausted.
Remediation
Users are advised to update to version 1.3 or later, where this vulnerability has been fixed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
