Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0193

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

A flaw was found in the WebSocket08FrameDecoder implementation that could allow a remote attacker to trigger an Out Of Memory Exception by issuing a series of TextWebSocketFrame and ContinuationWebSocketFrames. Depending on the server configuration, this could lead to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5nettyWill not fix
Red Hat JBoss Data Grid 6nettyNot affected
Red Hat JBoss Enterprise Application Platform 5nettyWill not fix
Red Hat JBoss Operations Network 3nettyAffected
Red Hat JBoss Portal 5nettyWill not fix
Red Hat JBoss SOA Platform 5nettyWill not fix
Red Hat Satellite 6nettyFix deferred
Red Hat Subscription Asset ManagernettyWill not fix
Red Hat JBoss A-MQ 6.1FixedRHSA-2014:135101.10.2014
Red Hat JBoss BPMS 6.0nettyFixedRHSA-2015:023417.02.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1092783netty: DoS via memory exhaustion during data aggregation

EPSS

Процентиль: 90%
0.04326
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

nvd
больше 12 лет назад

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

debian
больше 12 лет назад

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7. ...

github
больше 4 лет назад

Netty denial of service vulnerability

EPSS

Процентиль: 90%
0.04326
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2014-0193