CVE-2014-3488

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.4:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.5:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.6:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.7:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.6.8:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.8.1:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.9.0:*:*:*:*:*:*:*
cpe:2.3:a:netty:netty:3.9.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://netty.io/news/2014/06/11/3-9-2-Final.html - Vendor Advisory () http://netty.io/news/2014/06/11/3-9-2-Final.html - Vendor Advisory
References () http://secunia.com/advisories/59196 - () http://secunia.com/advisories/59196 -
References () https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994 - () https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994 -
References () https://github.com/netty/netty/issues/2562 - Exploit, Patch () https://github.com/netty/netty/issues/2562 - Exploit, Patch
References () https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html - () https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html -

Information

Published : 2014-07-31 14:55

Updated : 2024-11-21 02:08


NVD link : CVE-2014-3488

Mitre link : CVE-2014-3488

CVE.ORG link : CVE-2014-3488


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer