UBUNTU-CVE-2020-11612
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-11612
UBUNTU-CVE-2020-11612
Summary:
Details: The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
References: https://ubuntu.com/security/CVE-2020-11612, https://github.com/netty/netty/issues/6168, https://github.com/netty/netty/pull/9924, https://github.com/netty/netty/commit/1543218d3e7afcb33a90b728b14370395a3deca0, https://github.com/netty/netty/compare/netty-4.1.45.Final...netty-4.1.46.Final, https://lists.apache.org/thread.html/r14446ed58208cb6d97b6faa6ebf145f1cf2c70c0886c0c133f4d3b6f@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/r2958e4d49ee046e1e561e44fdc114a0d2285927501880f15852a9b53@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/r3195127e46c87a680b5d1d3733470f83b886bfd3b890c50df718bed1@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/r7836bbdbe95c99d4d725199f0c169927d4e87ba57e4beeeb699c097a@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/r8a654f11e1172b0effbfd6f8d5b6ca651ae4ac724a976923c268a42f@%3Ccommits.druid.apache.org%3E, https://lists.apache.org/thread.html/ra98e3a8541a09271f96478d5e22c7e3bd1afdf48641c8be25d62d9f9@%3Ccommits.druid.apache.org%3E, https://ubuntu.com/security/notices/USN-4600-2, https://ubuntu.com/security/notices/USN-6049-1, https://www.cve.org/CVERecord?id=CVE-2020-11612
Affected packages
Package
Name: netty
Purl: pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
