Описание
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
Комментарий
CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.20 (включая) до 4.0.37 (исключая)Версия от 4.1.0 (включая) до 4.1.1 (исключая)
Одно из
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:a:redhat:jboss_data_grid:7.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*
Конфигурация 3
cpe:2.3:a:apache:cassandra:3.11.4:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.0823
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-835
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 9 лет назад
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
CVSS3: 3.7
redhat
больше 9 лет назад
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
CVSS3: 7.5
debian
почти 9 лет назад
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and ...
EPSS
Процентиль: 92%
0.0823
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-835