CVE-2023-3635

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.08 % (35th)
0.08% Progress
Affected Products 1
Advisories 1

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

Weaknesses
CWE-195
Signed to Unsigned Conversion Error
CWE-681
Incorrect Conversion between Numeric Types
CVE Status
PUBLISHED
CNA
JFrog
Published Date
2023-07-12 19:15:08
(14 months ago)
Updated Date
2023-10-25 15:17:42
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Squareup Okio from 0.5.0 version and prior 1.17.6 version cpe:2.3:a:squareup:okio >= 0.5.0 < 1.17.6
  Squareup Okio from 2.0.0 version and prior 3.4.0 version cpe:2.3:a:squareup:okio >= 2.0.0 < 3.4.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...