VYPR

rpm package

opensuse/netty&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweed

Vulnerabilities (102)

  • CVE-2021-21290MedFeb 8, 2021
    affected < 4.1.60-1.4fixed 4.1.60-1.4

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file.

  • CVE-2020-11612HigApr 7, 2020
    affected < 4.1.60-1.4fixed 4.1.60-1.4

    The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.

Page 6 of 6