Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vjp-v76f-g363

Опубликовано: 09 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way

Impact

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well.

This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Impact

All users of SnappyFrameDecoder are affected and so the application may be in risk for a DoS attach due excessive memory usage.

References

https://github.com/netty/netty/blob/netty-4.1.67.Final/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.java#L79 https://github.com/netty/netty/blob/netty-4.1.67.Final/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.java#L171 https://github.com/netty/netty/blob/netty-4.1.67.Final/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.java#L185

Ссылки

Пакеты

Наименование

io.netty:netty-codec

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.1.68.Final

4.1.68.Final

Наименование

org.jboss.netty:netty

maven
Затронутые версииВерсия исправления

Отсутствует

Наименование

io.netty:netty

maven
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 85%
0.02383
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

CVSS3: 7.5
redhat
больше 4 лет назад

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

CVSS3: 7.5
nvd
больше 4 лет назад

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

CVSS3: 7.5
debian
больше 4 лет назад

The Snappy frame decoder function doesn't restrict the chunk length wh ...

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость функции декодирования кадров сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 85%
0.02383
Низкий

7.5 High

CVSS3

Дефекты

CWE-400