The Puppet Communications Protocol (PCP) broker incorrectly validates message header sizes. An attacker could use this vulnerability to crash the PCP broker, preventing commands from being sent to agents.
Reported by NCC Group.
Affected software versions:
Resolved in: