CVE-2014-3488
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
31/07/2014
Last modified:
12/04/2025
Description
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | 3.9.1.1 (including) | |
cpe:2.3:a:netty:netty:3.6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.6.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.8.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:netty:netty:3.9.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://netty.io/news/2014/06/11/3-9-2-Final.html
- http://secunia.com/advisories/59196
- https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994
- https://github.com/netty/netty/issues/2562
- https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html
- http://netty.io/news/2014/06/11/3-9-2-Final.html
- http://secunia.com/advisories/59196
- https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994
- https://github.com/netty/netty/issues/2562
- https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html