First published: Fri Jan 31 2020(Updated: )
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qpid-cpp | <0:1.36.0-30.el6_10a | 0:1.36.0-30.el6_10a |
redhat/qpid-proton | <0:0.31.0-3.el6_10 | 0:0.31.0-3.el6_10 |
redhat/qpid-cpp | <0:1.36.0-30.el7a | 0:1.36.0-30.el7a |
redhat/qpid-proton | <0:0.31.0-3.el7 | 0:0.31.0-3.el7 |
redhat/nodejs-rhea | <0:1.0.21-1.el8 | 0:1.0.21-1.el8 |
redhat/qpid-cpp | <0:1.39.0-5.el8a | 0:1.39.0-5.el8a |
redhat/qpid-proton | <0:0.31.0-3.el8 | 0:0.31.0-3.el8 |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el6ea | 0:4.1.48-1.Final_redhat_00001.1.el6ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el7ea | 0:2.1.3-1.redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el7ea | 0:1.6.2-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el7ea | 0:2.3.9-11.SP11_redhat_00001.1.el7ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el7ea | 0:3.2.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el7ea | 0:5.3.17-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el7ea | 0:6.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el7ea | 0:9.4.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el7ea | 0:1.4.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el7ea | 0:2.0.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el7ea | 0:2.1.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el7ea | 0:1.7.1-7.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el7ea | 0:3.7.8-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el7ea | 0:4.1.48-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el7ea | 0:2.0.30-4.SP4_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el7ea | 0:7.3.2-4.GA_redhat_00002.1.el7ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el7ea | 0:1.5.2-1.Final_redhat_00002.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el7ea | 0:1.10.7-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el7ea | 0:1.0.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el8ea | 0:2.1.3-1.redhat_00001.1.el8ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el8ea | 0:1.6.2-1.Final_redhat_00001.1.el8ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el8ea | 0:2.3.9-11.SP11_redhat_00001.1.el8ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el8ea | 0:3.2.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el8ea | 0:5.3.17-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el8ea | 0:6.0.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el8ea | 0:9.4.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el8ea | 0:1.4.22-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el8ea | 0:2.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el8ea | 0:2.1.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el8ea | 0:1.7.1-7.Final_redhat_00009.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el8ea | 0:3.7.8-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el8ea | 0:4.1.48-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el8ea | 0:2.0.30-4.SP4_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el8ea | 0:7.3.2-4.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el8ea | 0:1.5.2-1.Final_redhat_00002.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el8ea | 0:1.10.7-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el8ea | 0:1.0.22-1.Final_redhat_00001.1.el8ea |
redhat/candlepin | <0:3.1.26-1.el7 | 0:3.1.26-1.el7 |
Netty Netty | >=4.1<4.1.46 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =33 | |
NetApp OnCommand API Services | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Oracle Communications Brm - Elastic Charging Engine | =12.0.0.3 | |
Oracle Communications Cloud Native Core Service Communication Proxy | =1.5.2 | |
Oracle Communications Design Studio | =7.4.2 | |
Oracle Nosql Database | <20.3 | |
Oracle Siebel Core - Server Framework | <21.5 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Oracle Communications Messaging Server | =8.1 | |
ubuntu/netty | <1:4.1.48-1 | 1:4.1.48-1 |
ubuntu/netty | <1:4.1.7-4ubuntu0.1 | 1:4.1.7-4ubuntu0.1 |
ubuntu/netty | <1:4.0.34-1ubuntu0.1~ | 1:4.0.34-1ubuntu0.1~ |
ubuntu/netty | <1:4.1.45-1ubuntu0.1~ | 1:4.1.45-1ubuntu0.1~ |
redhat/netty | <4.1.46. | 4.1.46. |
debian/netty | 1:4.1.33-1+deb10u2 1:4.1.33-1+deb10u4 1:4.1.48-4+deb11u2 1:4.1.48-7+deb12u1 1:4.1.48-9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)