Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-37136

Опубликовано: 19 окт. 2021
Источник: debian

Описание

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nettyfixed1:4.1.48-6package
nettyno-dsastretchpackage

Примечания

  • https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv

  • Fixed by: https://github.com/netty/netty/commit/41d3d61a61608f2223bb364955ab2045dd5e4020 (netty-4.1.68.Final)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
redhat
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
nvd
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
github
больше 4 лет назад

Bzip2Decoder doesn't allow setting size restrictions for decompressed data

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость декодера Bzip2Decoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании