CVE-2023-50570: Medium severity Seancfoley Ipaddress vulnerability
Published Dec 29, 2023
·Updated
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop.
Affected Software
3 affected components
maven/com.github.seancfoley:ipaddress<=5.4.0
Seancfoley Ipaddress=5.1.0
IBM Concert Software<=1.0.0-3.0.0
Event History
Dec 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·03:30 PM
Jan 12, 2024
Withdrawn
via GitHub·05:47 PM
Sep 22, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50570?
CVE-2023-50570 has been reported to lead to an infinite loop under certain conditions, which can impact application performance.
2
How do I fix CVE-2023-50570?
To mitigate CVE-2023-50570, upgrading the IPAddress library to version 5.4.1 or later is recommended.
3
Which versions are affected by CVE-2023-50570?
CVE-2023-50570 affects IPAddress version 5.1.0 and potentially versions up to 5.4.0.
4
What conditions trigger the infinite loop in CVE-2023-50570?
The infinite loop in CVE-2023-50570 occurs when invalid arguments are supplied by the developer.
5
Is CVE-2023-50570 a critical vulnerability?
CVE-2023-50570 is not classified as critical but poses performance risks depending on input handling.