Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm9x-g8pc-w292

Опубликовано: 15 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of Service in Netty

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

Ссылки

Пакеты

Наименование

io.netty:netty-handler

maven
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.46

4.1.46

EPSS

Процентиль: 89%
0.04327
Низкий

7.5 High

CVSS3

Дефекты

CWE-119
CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

CVSS3: 7.5
redhat
около 6 лет назад

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

CVSS3: 7.5
nvd
почти 6 лет назад

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

CVSS3: 7.5
debian
почти 6 лет назад

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memo ...

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость реализации класса ZlibDecoders сетевого программного средства Netty, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 89%
0.04327
Низкий

7.5 High

CVSS3

Дефекты

CWE-119
CWE-400
CWE-770