Логотип exploitDog
bind:"BDU:2023-05355" OR bind:"CVE-2023-34462"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-05355" OR bind:"CVE-2023-34462"

Количество 8

Количество 8

fstec логотип

BDU:2023-05355

почти 3 года назад

Уязвимость компонента SniHandler сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20240514-04

почти 2 года назад

Множественные уязвимости netty

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-34462

почти 3 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-34462

почти 3 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-34462

почти 3 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-34462

почти 3 года назад

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2974-1

больше 2 лет назад

Security update for netty, netty-tcnative

EPSS: Низкий
github логотип

GHSA-6mjq-h674-j845

почти 3 года назад

netty-handler SniHandler 16MB allocation

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-05355

Уязвимость компонента SniHandler сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
1%
Низкий
почти 3 года назад
redos логотип
ROS-20240514-04

Множественные уязвимости netty

CVSS3: 7.5
почти 2 года назад
ubuntu логотип
CVE-2023-34462

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-34462

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-34462

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-34462

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2974-1

Security update for netty, netty-tcnative

1%
Низкий
больше 2 лет назад
github логотип
GHSA-6mjq-h674-j845

netty-handler SniHandler 16MB allocation

CVSS3: 6.5
1%
Низкий
почти 3 года назад

Уязвимостей на страницу