ZeroHour

CVE-2021-37137

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Vendors
nettyoraclequarkusnetappdebian
Products
netty, banking apis, banking digital experience, commerce guided search, communications brm - elastic charging engine, communications cloud native core binding support function, communications diameter signaling router, peoplesoft enterprise peopletools, webcenter portal, quarkus, oncommand insight, debian linux
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.