First published: Thu Feb 16 2023(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.3.7 GA includes security updates. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS (CVE-2022-41881)</li> <li> dev-java-snakeyaml: dev-java/snakeyaml: DoS via stack overflow (CVE-2022-41854)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:0577 is classified as moderate due to potential denial of service vulnerabilities.
To fix RHSA-2023:0577, upgrade to the latest release of Red Hat build of Eclipse Vert.x 4.3.7 GA that includes the security updates.
RHSA-2023:0577 addresses vulnerabilities including a stack exhaustion denial of service in the HAProxyMessageDecoder (CVE-2022-41881).
RHSA-2023:0577 is specifically applicable to the Red Hat build of Eclipse Vert.x 4.3.7 GA and its derivatives.
If you cannot apply the update for RHSA-2023:0577, consider implementing temporary mitigations to reduce exposure to the identified vulnerabilities.