The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
26 Apr 2022, 17:05
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:siebel_core_-_server_framework:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.5.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_design_studio:7.4.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.3:*:*:*:*:*:*:* cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r281882fdf9ea89aac02fd2f92786693a956aac2ce9840cce87c7df6b@%3Ccommits.zookeeper.apache.org%3E - Mailing List, Patch, Third Party Advisory | |
References | (DEBIAN) https://www.debian.org/security/2021/dsa-4885 - Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r7641ee788e1eb1be4bb206a7d15f8a64ec6ef23e5ec6132d5a567695@%3Cnotifications.zookeeper.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/ - Mailing List, Third Party Advisory | |
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2021.html - Patch, Third Party Advisory |
20 Apr 2022, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE | CWE-770 |
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2020-04-07 18:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-11612
Mitre link : CVE-2020-11612
CVE.ORG link : CVE-2020-11612
JSON object : View
Products Affected
oracle
- communications_messaging_server
- siebel_core_-_server_framework
- nosql_database
- communications_design_studio
- webcenter_portal
- communications_brm_-_elastic_charging_engine
- communications_cloud_native_core_service_communication_proxy
debian
- debian_linux
netapp
- oncommand_insight
- oncommand_api_services
- oncommand_workflow_automation
netty
- netty
fedoraproject
- fedora
CWE
CWE-770
Allocation of Resources Without Limits or Throttling