UBUNTU-CVE-2019-20445
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-20445
UBUNTU-CVE-2019-20445
Summary:
Details: HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
References: https://ubuntu.com/security/CVE-2019-20445, https://github.com/netty/netty/issues/9861, https://github.com/netty/netty/compare/netty-4.1.43.Final...netty-4.1.44.Final, https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E, https://ubuntu.com/security/notices/USN-4532-1, https://ubuntu.com/security/notices/USN-4600-1, https://ubuntu.com/security/notices/USN-4600-2, https://www.cve.org/CVERecord?id=CVE-2019-20445
Affected packages
Package
Name: netty
Purl: pkg:deb/ubuntu/netty?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
