First published: Wed Nov 10 2021(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.1.5 includes security updates, bug fixes, and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136)</li> <li> netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137)</li> For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2021:3959 has a moderate severity classification.
To fix RHSA-2021:3959, you should update to the latest version of Red Hat build of Eclipse Vert.x.
RHSA-2021:3959 addresses security issues related to netty-codec, specifically the Bzip2Decoder's size restrictions.
RHSA-2021:3959 affects the Red Hat build of Eclipse Vert.x 4.1.5.
There are no recommended workarounds for the vulnerabilities addressed in RHSA-2021:3959; the preferred solution is updating the software.