id: PYSEC-2021-68 details: An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is created, it will cause a memory leak that may result in a local denial of service (DoS). affected: - package: name: nfstream ecosystem: PyPI purl: pkg:pypi/nfstream ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 6.0.0 versions: - 0.1.0 - 0.2.0 - 0.3.0 - 0.3.1 - 0.4.0 - 0.5.0 - 1.0.0 - 1.0.1 - 1.0.2 - 1.0.3 - 1.1.0 - 1.1.1 - 1.1.2 - 1.1.3 - 1.1.4 - 1.1.5 - 1.1.6 - 1.1.7 - 1.1.8 - 1.2.0 - 1.2.1 - 2.0.0 - 2.0.1 - 3.0.0 - 3.0.1 - 3.0.2 - 3.0.3 - 3.0.4 - 3.1.0 - 3.1.1 - 3.1.2 - 3.2.0 - 3.2.1 - 3.2.2 - 4.0.0 - 4.0.1 - 5.0.0 - 5.1.0 - 5.1.1 - 5.1.2 - 5.1.3 - 5.1.4 - 5.1.5 - 5.1.6 - 5.2.0 references: - type: REPORT url: https://github.com/ntop/nDPI/issues/994 - type: ADVISORY url: https://github.com/advisories/GHSA-whmq-cfm5-j8mj aliases: - CVE-2020-25340 - GHSA-whmq-cfm5-j8mj modified: "2021-02-19T21:11:00Z" published: "2021-02-16T15:15:00Z"