CVE-2016-4970
high · 7.5handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
7.5
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2017-04-13
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-835
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| netty | netty | >= 4.0.20, < 4.0.37 |
| netty | netty | >= 4.1.0, < 4.1.1 |
| redhat | jboss_data_grid | 7.1 |
| redhat | jboss_middleware_text-only_advisories | 1.0 |
| apache | cassandra | 3.11.4 |
Check a specific version with /api/v1/cve/match.
References
- http://netty.io/news/2016/06/07/4-0-37-Final.html
- http://netty.io/news/2016/06/07/4-1-1-Final.html
- http://rhn.redhat.com/errata/RHSA-2017-0179.html
- http://rhn.redhat.com/errata/RHSA-2017-1097.html
- http://www.securityfocus.com/bid/96540
- https://bugzilla.redhat.com/show_bug.cgi?id=1343616
- https://github.com/netty/netty/pull/5364
- https://lists.apache.org/thread.html/afaa5860e3a6d327eb96c3d82cbd2f5996de815a16854ed1ad310144%40%3Ccommits.cassandra.apache.org%3E
- https://wiki.opendaylight.org/view/Security_Advisories
- http://netty.io/news/2016/06/07/4-0-37-Final.html
- http://netty.io/news/2016/06/07/4-1-1-Final.html
- http://rhn.redhat.com/errata/RHSA-2017-0179.html
- http://rhn.redhat.com/errata/RHSA-2017-1097.html
- http://www.securityfocus.com/bid/96540
- https://bugzilla.redhat.com/show_bug.cgi?id=1343616
- https://github.com/netty/netty/pull/5364
- https://lists.apache.org/thread.html/afaa5860e3a6d327eb96c3d82cbd2f5996de815a16854ed1ad310144%40%3Ccommits.cassandra.apache.org%3E
- https://wiki.opendaylight.org/view/Security_Advisories
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-4970