Описание
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
An infinite-loop vulnerability was discovered in Netty's OpenSslEngine handling of renegotiation. An attacker could exploit this flaw to cause a denial of service. Note: Netty is only vulnerable if renegotiation is enabled (default setting).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | netty | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | netty | Not affected | ||
| Red Hat JBoss BRMS 6 | netty | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | netty | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | netty | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | netty | Will not fix | ||
| Red Hat JBoss Fuse 6 | camel | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | netty | Not affected | ||
| Red Hat JBoss Operations Network 3 | netty | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | netty | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and ...
EPSS
3.7 Low
CVSS3
4.3 Medium
CVSS2