The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://netty.io/news/2014/06/11/3-9-2-Final.html - Vendor Advisory | |
References | () http://secunia.com/advisories/59196 - | |
References | () https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994 - | |
References | () https://github.com/netty/netty/issues/2562 - Exploit, Patch | |
References | () https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html - |
Information
Published : 2014-07-31 14:55
Updated : 2024-11-21 02:08
NVD link : CVE-2014-3488
Mitre link : CVE-2014-3488
CVE.ORG link : CVE-2014-3488
JSON object : View
Products Affected
netty
- netty
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer