CVE-2021-37136

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
JFROGCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
nettynetty
𝑥
< 4.1.68
quarkusquarkus
𝑥
< 2.2.4
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
18.1
oraclebanking_digital_experience
18.2
oraclebanking_digital_experience
18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclecoherence
12.2.1.4.0
oraclecoherence
14.1.1.0.0
oraclecommerce_guided_search
11.3.2
oraclecommunications_brm_-_elastic_charging_engine
𝑥
< 12.0.0.4.6
oraclecommunications_cloud_native_core_binding_support_function
1.10.0
oraclecommunications_cloud_native_core_binding_support_function
1.11.0
oraclecommunications_cloud_native_core_network_slice_selection_function
1.8.0
oraclecommunications_cloud_native_core_policy
1.15.0
oraclecommunications_cloud_native_core_security_edge_protection_proxy
1.7.0
oraclecommunications_cloud_native_core_unified_data_repository
1.15.0
oraclecommunications_diameter_signaling_router
8.0.0.0 ≤
𝑥
≤ 8.5.0.2
oraclecommunications_instant_messaging_server
8.1
oraclehelidon
1.4.10
oraclehelidon
2.4.0
oraclepeoplesoft_enterprise_peopletools
8.48
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
netapponcommand_insight
-
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bullseye (security)
1:4.1.48-4+deb11u2
fixed
bullseye
1:4.1.48-4+deb11u2
fixed
stretch
no-dsa
bookworm
1:4.1.48-7+deb12u1
fixed
bookworm (security)
1:4.1.48-7+deb12u1
fixed
sid
1:4.1.48-10
fixed
trixie
1:4.1.48-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
Fixed 1:4.1.48-5ubuntu0.1
released
jammy
Fixed 1:4.1.48-4+deb11u1build0.22.04.1
released
impish
ignored
hirsute
ignored
focal
Fixed 1:4.1.45-1ubuntu0.1~esm1
released
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm2
released
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm1
released
trusty
needs-triage
References