Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
White Paper: DTLS 'ClientHello' Race Conditions in WebRTC Implementations [pdf] (enablesecurity.com)
1 point by obscure6 on Oct 22, 2024 | hide | past | favorite | 1 comment


We've discovered a critical vulnerability affecting several WebRTC implementations, including RTPEngine, Asterisk, FreeSWITCH, and Skype (PSTN). Our research reveals that these systems fail to properly verify the origin of DTLS "ClientHello" messages, potentially leading to denial of service attacks. This isn't a specification bug, but a common implementation oversight.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: