Логотип exploitDog
bind:CVE-2021-32781
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-32781

Количество 6

Количество 6

redhat логотип

CVE-2021-32781

около 4 лет назад

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-32781

около 4 лет назад

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json-tr

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2021-32781

около 4 лет назад

Envoy is an open source L7 proxy and communication bus designed for la ...

CVSS3: 8.6
EPSS: Низкий
oracle-oval логотип

ELSA-2021-9525

почти 4 года назад

ELSA-2021-9525: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-9546

почти 4 года назад

ELSA-2021-9546: olcne istio istio kubernetes security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-9526

почти 4 года назад

ELSA-2021-9526: olcne security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json...

CVSS3: 7.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions after Envoy sends a locally generated response it must stop further processing of request or response data. However when local response is generated due the internal buffer overflow while request or response is processed by the filter chain the operation may not be stopped completely and result in accessing a freed memory block. A specifically constructed request delivered by an untrusted downstream or upstream peer in the presence of extensions that modify and increase the size of request or response bodies resulting in a Denial of Service when using extensions that modify and increase the size of request or response bodies, such as decompressor filter. Envoy versions 1.19.1, 1.18.4, 1.17.4, 1.16.5 contain fixes to address incomplete termination of request processing after locally generated response. As a workaround disable Envoy's decompressor, json-tr

CVSS3: 8.6
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-32781

Envoy is an open source L7 proxy and communication bus designed for la ...

CVSS3: 8.6
0%
Низкий
около 4 лет назад
oracle-oval логотип
ELSA-2021-9525

ELSA-2021-9525: olcne security update (IMPORTANT)

почти 4 года назад
oracle-oval логотип
ELSA-2021-9546

ELSA-2021-9546: olcne istio istio kubernetes security update (IMPORTANT)

почти 4 года назад
oracle-oval логотип
ELSA-2021-9526

ELSA-2021-9526: olcne security update (IMPORTANT)

почти 4 года назад

Уязвимостей на страницу