[MAVEN:GHSA-9959-6P3M-WXPC] Denial of service in Netty

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

Package Affected Version
pkg:maven/io.netty/netty-handler < 3.9.2
Package Fixed Version
pkg:maven/io.netty/netty-handler = 3.9.2
ID
MAVEN:GHSA-9959-6P3M-WXPC
Severity
moderate
URL
https://github.com/advisories/GHSA-9959-6p3m-wxpc
Published
2020-06-30T21:01:31
(4 years ago)
Modified
2023-01-09T05:03:18
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.netty/netty-handler io.netty netty-handler < 3.9.2
Fixed pkg:maven/io.netty/netty-handler io.netty netty-handler = 3.9.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...