CVE-2018-10657
published 2018-05-02CVE-2018-10657: Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to…
PriorityP272high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.51%
71.6th percentile
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 0.28.1+dfsg-1 (forky) | matrix-synapse 0.28.1+dfsg-1 (forky) |
| matrix | synapse | < 0.28.1 | 0.28.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect federation events where the 'depth' field is set to the maximum 64-bit signed integer value (9223372036854775807 / 2^63 - 1), which is the malicious payload used to render Matrix rooms unusable. ↗
- →Monitor Matrix Synapse federation traffic for events with anomalously large depth values; exploitation was observed in the wild in April 2018. ↗
- ·Only Matrix Synapse versions before 0.28.1 are vulnerable; upgrade to 0.28.1 or later (Debian: 0.28.1+dfsg-1, Fedora: 0.28.1-1.fc28) to remediate. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2023-05-16·CVSS 7.5
CVE-2019-5885 [HIGH] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a re
Debian
CVE-2018-10657: matrix-synapse - Matrix Synapse before 0.28.1 is prone to a denial of service flaw where maliciou...
vendor_debian·2018·CVSS 7.5
CVE-2018-10657 [HIGH] CVE-2018-10657: matrix-synapse - Matrix Synapse before 0.28.1 is prone to a denial of service flaw where maliciou...
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Scope: local
forky: resolved (fixed in 0.28.1+dfsg-1)
sid: resolved (fixed in 0.28.1+dfsg-1)
OSV
matrix-synapse vulnerabilities
osv·2023-05-16·CVSS 7.5
CVE-2019-18835 [HIGH] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform
sp
GHSA
Matrix Synapse DoS
ghsa·2022-05-14
CVE-2018-10657 [HIGH] CWE-20 Matrix Synapse DoS
Matrix Synapse DoS
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 263 - 1 render rooms unusable, related to `federation/federation_base.py` and `handlers/message.py`, as exploited in the wild in April 2018.
OSV
Matrix Synapse DoS
osv·2022-05-14
CVE-2018-10657 [HIGH] Matrix Synapse DoS
Matrix Synapse DoS
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 263 - 1 render rooms unusable, related to `federation/federation_base.py` and `handlers/message.py`, as exploited in the wild in April 2018.
OSV
CVE-2018-10657: Matrix Synapse before 0
osv·2018-05-02·CVSS 7.5
CVE-2018-10657 [HIGH] CVE-2018-10657: Matrix Synapse before 0
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
VulnCheck
matrix synapse Improper Input Validation
vulncheck·2018·CVSS 7.5
CVE-2018-10657 [HIGH] matrix synapse Improper Input Validation
matrix synapse Improper Input Validation
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Affected: matrix synapse
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/; https://www.cve.org/CVERecord?id=CVE-2018-10657
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable [fedora-all]
bugzilla·2018-05-04·CVSS 7.5
CVE-2018-10657 [HIGH] CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable [fedora-all]
CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable
bugzilla·2018-05-04·CVSS 7.5
CVE-2018-10657 [HIGH] CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable
CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
External Reference:
https://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/
Upstream Patch:
https://github.com/matrix-org/synapse/commit/33f469ba19586bbafa0cf2c7d7c35463bdab87eb
Discussion:
Created matrix-synapse tracking bugs for this issue:
Affects: fedora-all [bug 1574780]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a pa
https://github.com/matrix-org/synapse/commit/33f469ba19586bbafa0cf2c7d7c35463bdab87ebhttps://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/https://github.com/matrix-org/synapse/commit/33f469ba19586bbafa0cf2c7d7c35463bdab87ebhttps://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/
2018-05-02
Published
Exploited in the wild