Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4970

Опубликовано: 07 июн. 2016
Источник: redhat
CVSS3: 3.7
CVSS2: 4.3
EPSS Средний

Описание

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

An infinite-loop vulnerability was discovered in Netty's OpenSslEngine handling of renegotiation. An attacker could exploit this flaw to cause a denial of service. Note: Netty is only vulnerable if renegotiation is enabled (default setting).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6nettyNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolsnettyNot affected
Red Hat JBoss BRMS 6nettyNot affected
Red Hat JBoss Data Virtualization 6nettyNot affected
Red Hat JBoss Enterprise Application Platform 6nettyNot affected
Red Hat JBoss Enterprise Application Platform 7nettyWill not fix
Red Hat JBoss Fuse 6camelAffected
Red Hat JBoss Fuse Service Works 6nettyNot affected
Red Hat JBoss Operations Network 3nettyWill not fix
Red Hat OpenShift Enterprise 2nettyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1343616netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl

EPSS

Процентиль: 96%
0.11259
Средний

3.7 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

CVSS3: 7.5
nvd
больше 9 лет назад

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

CVSS3: 7.5
debian
больше 9 лет назад

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and ...

CVSS3: 7.5
github
больше 4 лет назад

Loop with Unreachable Exit Condition in Netty

EPSS

Процентиль: 96%
0.11259
Средний

3.7 Low

CVSS3

4.3 Medium

CVSS2