Описание
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
A flaw was found in codec-haproxy from the Netty project. This flaw allows an attacker to build a malformed crafted message and cause infinite recursion, causing stack exhaustion and leading to a denial of service (DoS).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | codec-haproxy | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
| Migration Toolkit for Applications 6 | io.netty-netty-parent | Affected | ||
| Migration Toolkit for Applications 6 | org.jboss.windup.plugin-windup-maven-plugin-parent | Affected | ||
| Migration Toolkit for Applications 6 | org.jboss.windup-windup-parent | Affected | ||
| Migration Toolkit for Runtimes | org.jboss.windup-windup-parent | Affected | ||
| Red Hat build of Debezium 1 | codec-haproxy | Will not fix | ||
| Red Hat build of Quarkus | codec-haproxy | Will not fix | ||
| Red Hat JBoss Data Grid 7 | codec-haproxy | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | codec-haproxy | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Netty project is an event-driven asynchronous network application fram ...
Уязвимость сетевого программного средства Netty связана с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3