First published: Mon Mar 01 2021(Updated: )
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE | >=4.0.0-9<=5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25829 has a medium severity rating due to its potential for denial of service attacks.
To address CVE-2021-25829, users should upgrade ONLYOFFICE DocumentServer to a version later than 5.6.3.
CVE-2021-25829 is a denial of service vulnerability caused by improper binary stream data handling.
Versions from 4.0.0-9 to 5.6.3 of ONLYOFFICE DocumentServer are vulnerable to CVE-2021-25829.
An attacker exploiting CVE-2021-25829 can create conditions that may lead to a denial of service and shutdown the target server.