CVE-2016-4970

CWE-8359 documents7 sources
Severity
7.5HIGH
EPSS
8.2%
top 7.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 13

Description

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Mavenio.netty:netty-handler4.0.0.Alpha14.0.37.Final+1
NVDnetty/netty4.0.204.0.37+1
Debiannetty< 1:4.0.37-1+3
NVDapache/cassandra3.11.4

Patches

🔴Vulnerability Details

4
GHSA
Loop with Unreachable Exit Condition in Netty2022-05-13
OSV
Loop with Unreachable Exit Condition in Netty2022-05-13
OSV
CVE-2016-4970: handler/ssl/OpenSslEngine2017-04-13
CVEList
CVE-2016-4970: handler/ssl/OpenSslEngine2017-04-13

📋Vendor Advisories

2
Red Hat
netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl2016-06-07
Debian
CVE-2016-4970: netty - handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x befo...2016

💬Community

2
Bugzilla
CVE-2016-4970 netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl [fedora-all]2016-06-17
Bugzilla
CVE-2016-4970 netty: Infinite loop vulnerability when handling renegotiation using SslProvider.OpenSsl2016-06-07