USN-7284-1: Netty vulnerabilities
Jonathan Leitschuh discovered that Netty did not correctly handle file permissions when writing temporary files. An attacker could possibly use this issue to leak sensitive information. (CVE-2022-24823) It was discovered that Netty did not correctly handle limiting the number of fields when decoding a HTTP request. An attacker could possibly use issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-29025)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7284-1?
The severity of USN-7284-1 is considered high due to potential information leakage.
How do I fix USN-7284-1?
You can fix USN-7284-1 by upgrading to the latest version of libnetty-java specified in the advisory.
What versions of Ubuntu are affected by USN-7284-1?
USN-7284-1 affects multiple versions of Ubuntu including 16.04, 18.04, 20.04, 22.04, and 24.04.
What is the vulnerability associated with USN-7284-1?
The vulnerability associated with USN-7284-1 is CVE-2022-24823, which deals with improper file permission handling.
Who discovered the issue in USN-7284-1?
The issue in USN-7284-1 was discovered by Jonathan Leitschuh.