Vulnerability Name: | CVE-2016-4970 (CCN-122029) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-06-07 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2016-06-07 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2021-02-14 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-835 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-4970 Source: CCN Type: Netty Web site Netty Source: CONFIRM Type: Release Notes, Vendor Advisory http://netty.io/news/2016/06/07/4-0-37-Final.html Source: CONFIRM Type: Release Notes, Vendor Advisory http://netty.io/news/2016/06/07/4-1-1-Final.html Source: REDHAT Type: Third Party Advisory RHSA-2017:0179 Source: REDHAT Type: Third Party Advisory RHSA-2017:1097 Source: CCN Type: IBM Security Bulletin 1999185 (Development Package for Apache Spark) Vulnerability in dependent component shipped in IBM Development Package for Apache Spark (CVE-2016-4970) Source: CCN Type: IBM Security Bulletin 2015818 (Security QRadar SIEM) IBM QRadar SIEM contains vulnerable components and libraries. (CVE-2014-0193, CVE-2016-4970) Source: BID Type: Third Party Advisory, VDB Entry 96540 Source: CCN Type: BID-96540 IBM Development Package for Apache Spark CVE-2016-4970 Denial of Service Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1343616 (CVE-2016-4970) CVE-2016-4970 netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl Source: CONFIRM Type: Issue Tracking, Third Party Advisory, VDB Entry https://bugzilla.redhat.com/show_bug.cgi?id=1343616 Source: XF Type: UNKNOWN netty-cve20164970-dos(122029) Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/netty/netty/pull/5364 Source: MLIST Type: Mailing List, Third Party Advisory [cassandra-commits] 20191112 [jira] [Created] (CASSANDRA-15412) Security vulnerability CVE-2016-4970 for Netty Source: CONFIRM Type: Third Party Advisory https://wiki.opendaylight.org/view/Security_Advisories Source: CCN Type: IBM Security Bulletin 6456763 (WebSphere eXtreme Scale) Multiple vulnerabilities in IBM WebSphere eXtreme Scale Liberty Deployment. | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |