Логотип exploitDog
bind:CVE-2022-29225
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29225

Количество 8

Количество 8

redhat логотип

CVE-2022-29225

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-29225

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-29225

около 3 лет назад

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-04157

около 3 лет назад

Уязвимость компонента decode/encodeBody прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9589

около 3 лет назад

ELSA-2022-9589: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9588

около 3 лет назад

ELSA-2022-9588: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9587

около 3 лет назад

ELSA-2022-9587: olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-9586

около 3 лет назад

ELSA-2022-9586: olcne security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-29225

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-29225

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-29225

Envoy is a cloud-native high-performance proxy. In versions prior to 1 ...

CVSS3: 7.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-04157

Уязвимость компонента decode/encodeBody прокси-сервера Envoy, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-9589

ELSA-2022-9589: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9588

ELSA-2022-9588: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9587

ELSA-2022-9587: olcne security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-9586

ELSA-2022-9586: olcne security update (IMPORTANT)

около 3 лет назад

Уязвимостей на страницу