CVE-2024-25678: Critical severity Litespeedtech Lsquic vulnerability
Published Feb 9, 2024
·Updated
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
Affected Software
1 affected component
Litespeedtech Lsquic<4.0.4
Remediation
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25678?
CVE-2024-25678 has been assigned a Medium severity level due to the potential for DCID validation mishandling.
2
How do I fix CVE-2024-25678?
To fix CVE-2024-25678, upgrade the LiteSpeed QUIC (LSQUIC) Library to version 4.0.4 or later.
3
What software is affected by CVE-2024-25678?
CVE-2024-25678 affects LiteSpeed QUIC (LSQUIC) Library versions prior to 4.0.4.
4
What type of vulnerability is CVE-2024-25678?
CVE-2024-25678 is a validation vulnerability related to DCID handling in the LiteSpeed QUIC Library.
5
When was CVE-2024-25678 disclosed?
CVE-2024-25678 was disclosed in the year 2024.