Required CVE Record Information
Description
In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fixed in 1.0.1.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
6.3 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://github.com/kylebrowning/APNSwift/security/advisories/GHSA-qh2w-vjxg-mjcg x_transferred
- https://github.com/kylebrowning/APNSwift/issues/31 x_transferred
- https://github.com/kylebrowning/APNSwift/pull/32 x_transferred
- https://github.com/kylebrowning/APNSwift/commit/97fa7f69dcdd89168fff84e0ba8f999881ee3d3f x_transferred