CVE Database
/

CVE-2021-37136

Back to search

CVE-2021-37136

Published: Oct 19, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

VendorProductVersions

The Netty project

Netty

affected
unspecified - < 4.1.68Final

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now