PT-2020-5478 · Netty+4 · Netty+4
Published
2020-04-07
·
Updated
2024-06-15
·
CVE-2020-11612
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netty versions 4.1.x through 4.1.45
Description
The issue is related to the ZlibDecoders class in Netty, which allows for unbounded memory allocation while decoding a ZlibEncoded byte stream. This can be exploited by an attacker to impact the confidentiality, integrity, and availability of protected information by sending a large ZlibEncoded byte stream to the Netty server, forcing it to allocate all of its free memory to a single decoder.
Recommendations
For Netty versions 4.1.x through 4.1.45, update to version 4.1.46 or later to resolve the issue. As a temporary workaround, consider restricting the size of incoming ZlibEncoded byte streams to prevent excessive memory allocation.
Exploit
Fix
Allocation of Resources Without Limits
Buffer Overflow
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Netty
Suse
Ubuntu