Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3488

Опубликовано: 11 июн. 2014
Источник: redhat
CVSS2: 7.8
EPSS Низкий

Описание

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

Отчет

Netty versions as shipped by Red Hat products are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6nettyNot affected
Red Hat JBoss BRMS 6nettyNot affected
Red Hat JBoss Enterprise Application Platform 5nettyNot affected
Red Hat JBoss Enterprise Application Platform 6nettyNot affected
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat JBoss Fuse Service Works 6nettyNot affected
Red Hat JBoss Portal 5nettyNot affected
Red Hat JBoss Portal 6nettyNot affected
Red Hat Satellite 6nettyNot affected
Red Hat Software Collectionsthermostat1-nettyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1107983Netty: DoS by CPU exhaustion when using malicious SSL packets

EPSS

Процентиль: 75%
0.00867
Низкий

7.8 High

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

nvd
больше 11 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

debian
больше 11 лет назад

The SslHandler in Netty before 3.9.2 allows remote attackers to cause ...

github
больше 5 лет назад

Denial of service in Netty

EPSS

Процентиль: 75%
0.00867
Низкий

7.8 High

CVSS2