Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37136

Опубликовано: 09 сент. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

A flaw was found in Netty's netty-codec due to size restrictions for decompressed data in the Bzip2Decoder. By sending a specially-crafted input, a remote attacker could cause a denial of service.

Отчет

In the OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack ship the vulnerable version of netty-codec package. Since the release of OCP 4.6, the Metering product has been deprecated [1], so the affected components are marked as wontfix. This may be fixed in the future. Starting in OCP 4.7, the elasticsearch component is shipping as a part of the OpenShift Logging product (openshift-logging/elasticsearch6-rhel8). The elasticsearch component delivered in OCP 4.6 is marked as Out of support scope because these versions are already under Maintenance Phase of the support. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2netty-codecAffected
Red Hat BPM Suite 6netty-codecOut of support scope
Red Hat build of Quarkusnetty-codecAffected
Red Hat Integration Camel K 1netty-codecAffected
Red Hat Integration Service Registrynetty-codecNot affected
Red Hat JBoss BRMS 6netty-codecOut of support scope
Red Hat JBoss Data Grid 7netty-codecOut of support scope
Red Hat JBoss Data Virtualization 6netty-codecOut of support scope
Red Hat JBoss Fuse 6netty-codecOut of support scope
Red Hat JBoss Fuse Service Works 6netty-codecOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2004133netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data

EPSS

Процентиль: 57%
0.00352
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
nvd
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
debian
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size re ...

CVSS3: 7.5
github
больше 4 лет назад

Bzip2Decoder doesn't allow setting size restrictions for decompressed data

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость декодера Bzip2Decoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 57%
0.00352
Низкий

7.5 High

CVSS3

Уязвимость CVE-2021-37136