Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-37136

Опубликовано: 19 окт. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

released

4.1.48-6
esm-apps/bionic

released

1:4.1.7-4ubuntu0.1+esm2
esm-apps/focal

released

1:4.1.45-1ubuntu0.1~esm1
esm-apps/jammy

released

1:4.1.48-4+deb11u1build0.22.04.1
esm-apps/noble

released

4.1.48-6
esm-apps/xenial

released

1:4.0.34-1ubuntu0.1~esm1
esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needed
hirsute

ignored

end of life

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
nvd
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

CVSS3: 7.5
debian
больше 4 лет назад

The Bzip2 decompression decoder function doesn't allow setting size re ...

CVSS3: 7.5
github
больше 4 лет назад

Bzip2Decoder doesn't allow setting size restrictions for decompressed data

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость декодера Bzip2Decoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

5 Medium

CVSS2

7.5 High

CVSS3