CVE-2021-41973

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91.11%
Affected Products (NVD)
VendorProductVersion
apachemina
𝑥
< 2.0.22
apachemina
2.1.0 ≤
𝑥
< 2.1.5
oraclebanking_payments
14.5
oraclebanking_trade_finance_process_management
14.5
oraclebanking_treasury_management
14.5
oraclecommunications_cloud_native_core_console
1.9.0
oraclecustomer_management_and_segmentation_foundation
18.0
oraclecustomer_management_and_segmentation_foundation
19.0
oracleflexcube_universal_banking
14.0 ≤
𝑥
≤ 14.3
oracleflexcube_universal_banking
14.5
oraclefusion_middleware_common_libraries_and_tools
12.2.1.3.0
oraclefusion_middleware_common_libraries_and_tools
12.2.1.4.0
oraclefusion_middleware_common_libraries_and_tools
14.1.1.0.0
oracleoss_support_tools
2.12.42
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mina
bookworm
1.1.7.dfsg-13
fixed
bullseye
1.1.7.dfsg-13
fixed
mina2
bookworm
2.2.1-3
fixed
bullseye
postponed
forky
2.2.1-4
fixed
sid
2.2.1-4
fixed
trixie
2.2.1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mina
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
dne
resolute
dne
xenial
ignored
mina2
bionic
needs-triage
focal
needs-triage
jammy
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
xenial
ignored