Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3488

Опубликовано: 11 июн. 2014
Источник: redhat
CVSS2: 7.8
EPSS Низкий

Описание

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

Отчет

Netty versions as shipped by Red Hat products are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6nettyNot affected
Red Hat JBoss BRMS 6nettyNot affected
Red Hat JBoss Enterprise Application Platform 5nettyNot affected
Red Hat JBoss Enterprise Application Platform 6nettyNot affected
Red Hat JBoss Fuse Service Works 6nettyNot affected
Red Hat JBoss Portal 5nettyNot affected
Red Hat JBoss Portal 6nettyNot affected
Red Hat Satellite 6nettyNot affected
Red Hat Software Collectionsthermostat1-nettyNot affected
Red Hat Subscription Asset ManagernettyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1107983Netty: DoS by CPU exhaustion when using malicious SSL packets

EPSS

Процентиль: 90%
0.04222
Низкий

7.8 High

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

nvd
около 12 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

debian
около 12 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause ...

github
около 6 лет назад

Denial of service in Netty

EPSS

Процентиль: 90%
0.04222
Низкий

7.8 High

CVSS2