CVE-2020-11612
07.04.2020, 18:15
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.Enginsight
Vendor | Product | Version |
---|---|---|
netty | netty | 4.1 ≤ 𝑥 < 4.1.46 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
netapp | oncommand_api_services | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
oracle | communications_brm_-_elastic_charging_engine | 12.0.0.3 |
oracle | communications_cloud_native_core_service_communication_proxy | 1.5.2 |
oracle | communications_design_studio | 7.4.2 |
oracle | nosql_database | 𝑥 < 20.3 |
oracle | siebel_core_-_server_framework | 𝑥 < 21.5 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
oracle | communications_messaging_server | 8.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
netty |
|
References