CVE-2021-37136

🟡 Monitoruj

Brak ograniczeń rozmiaru w dekoderze Bzip2 prowadzi do ataku DoS przez OOME.

CVSS
7.5
EPSS
5.9%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)5.9%
Opublikowano (NVD)2021-10-19 15:15:07 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:17:10 UTC
Referencje