Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:2096-1

Опубликовано: 04 мая 2023
Источник: suse-cvrf

Описание

Security update for netty, netty-tcnative

This update for netty, netty-tcnative fixes the following issues:

netty:

  • Security fixes included in this version update from 4.1.75 to 4.1.90:

    • CVE-2022-24823: Local Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary files for Java 6 and lower in io.netty:netty-codec-http (bsc#1199338)
    • CVE-2022-41881: HAProxyMessageDecoder Stack Exhaustion DoS (bsc#1206360)
    • CVE-2022-41915: HTTP Response splitting from assigning header value iterator (bsc#1206379)
  • Other non-security bug fixes included in this version update from 4.1.75 to 4.1.90:

netty-tcnative:

  • New artifact named netty-tcnative-classes, provided by this update is required by netty 4.1.90 which contains important security updates
  • No formal changelog present. This artifact is closely bound to the netty releases

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
netty-4.1.90-150200.4.14.1
Image server-image
netty-4.1.90-150200.4.14.1
SUSE Enterprise Storage 7
netty-tcnative-2.0.59-150200.3.10.1
SUSE Enterprise Storage 7.1
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Module for Development Tools 15 SP4
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Real Time 15 SP3
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Server 15 SP2-LTSS
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Server 15 SP3-LTSS
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
netty-tcnative-2.0.59-150200.3.10.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
netty-tcnative-2.0.59-150200.3.10.1
openSUSE Leap 15.4
netty-4.1.90-150200.4.14.1
netty-javadoc-4.1.90-150200.4.14.1
netty-poms-4.1.90-150200.4.14.1
netty-tcnative-2.0.59-150200.3.10.1
netty-tcnative-javadoc-2.0.59-150200.3.10.1

Описание

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:netty-4.1.90-150200.4.14.1
Image server-image:netty-4.1.90-150200.4.14.1
SUSE Enterprise Storage 7.1:netty-tcnative-2.0.59-150200.3.10.1
SUSE Enterprise Storage 7:netty-tcnative-2.0.59-150200.3.10.1

Ссылки

Описание

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:netty-4.1.90-150200.4.14.1
Image server-image:netty-4.1.90-150200.4.14.1
SUSE Enterprise Storage 7.1:netty-tcnative-2.0.59-150200.3.10.1
SUSE Enterprise Storage 7:netty-tcnative-2.0.59-150200.3.10.1

Ссылки

Описание

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:netty-4.1.90-150200.4.14.1
Image server-image:netty-4.1.90-150200.4.14.1
SUSE Enterprise Storage 7.1:netty-tcnative-2.0.59-150200.3.10.1
SUSE Enterprise Storage 7:netty-tcnative-2.0.59-150200.3.10.1

Ссылки
Уязвимость SUSE-SU-2023:2096-1