CVE-2021-37136
🟡 Monitoruj
Brak ograniczeń rozmiaru w dekoderze Bzip2 prowadzi do ataku DoS przez OOME.
CVSS
7.5
EPSS
5.9%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.9% |
| Opublikowano (NVD) | 2021-10-19 15:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:10 UTC |
Referencje
- https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv ([email protected]) [Third Party Advisory]
- https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3E ([email protected])
- https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html ([email protected]) [Mailing List, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20220210-0012/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2023/dsa-5316 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujan2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html ([email protected]) [Patch, Third Party Advisory]