See how ion-dtn compares to other vendors in security performance
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsecutil.c passes bundle->payload.length to zcoclone() without validating it against zero, causing a failed CHKZERO assertion that triggers smAbort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.