Описание
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
A flaw was found in codec-haproxy from the Netty project. This flaw allows an attacker to build a malformed crafted message and cause infinite recursion, causing stack exhaustion and leading to a denial of service (DoS).
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
A-MQ Clients 2 | codec-haproxy | Will not fix | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | ||
Migration Toolkit for Applications 6 | io.netty-netty-parent | Affected | ||
Migration Toolkit for Applications 6 | org.jboss.windup.plugin-windup-maven-plugin-parent | Affected | ||
Migration Toolkit for Applications 6 | org.jboss.windup-windup-parent | Affected | ||
Migration Toolkit for Runtimes | org.jboss.windup-windup-parent | Affected | ||
Red Hat build of Debezium 1 | codec-haproxy | Will not fix | ||
Red Hat build of Quarkus | codec-haproxy | Will not fix | ||
Red Hat JBoss Data Grid 7 | codec-haproxy | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform Expansion Pack | codec-haproxy | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Netty project is an event-driven asynchronous network application fram ...
Уязвимость сетевого программного средства Netty связана с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3