CVE-2020-14340
published 2021-06-02CVE-2020-14340: A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It…
PriorityP426medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.22%
80.7th percentile
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jboss-xnio | < jboss-xnio 3.8.2-1 (bookworm) | jboss-xnio 3.8.2-1 (bookworm) |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| redhat | jboss_brms | — | — |
| redhat | jboss_brms | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_data_virtualization | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | jboss_fuse | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_soa_platform | — | — |
| redhat | xnio | — | — |
| redhat | xnio | — | — |
| redhat | xnio | >= 3.6.1 < 3.7.9 | 3.7.9 |
| redhat | xnio | >= 3.8.0 < 3.8.2 | 3.8.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Uncontrolled Resource Consumption in XNIO
osv·2021-06-08
CVE-2020-14340 [MEDIUM] Uncontrolled Resource Consumption in XNIO
Uncontrolled Resource Consumption in XNIO
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
GHSA
Uncontrolled Resource Consumption in XNIO
ghsa·2021-06-08
CVE-2020-14340 [MEDIUM] CWE-400 Uncontrolled Resource Consumption in XNIO
Uncontrolled Resource Consumption in XNIO
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
OSV
CVE-2020-14340: A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cy
osv·2021-06-02·CVSS 5.9
CVE-2020-14340 [MEDIUM] CVE-2020-14340: A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cy
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (XNIO) — CVE-2020-14340
vendor_oracle·2022-04-15·CVSS 5.9
CVE-2020-14340 [MEDIUM] Oracle Oracle Communications Risk Matrix: CNC Console (XNIO) — CVE-2020-14340
Oracle Oracle Communications Risk Matrix: CNC Console (XNIO) vulnerability
CVE: CVE-2020-14340
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Network Repository Function (XNIO) — CVE-2020-14340
vendor_oracle·2022-01-15·CVSS 5.9
CVE-2020-14340 [MEDIUM] Oracle Oracle Communications Risk Matrix: Network Repository Function (XNIO) — CVE-2020-14340
Oracle Oracle Communications Risk Matrix: Network Repository Function (XNIO) vulnerability
CVE: CVE-2020-14340
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
vendor_redhat·2020-07-24·CVSS 5.9
CVE-2020-14340 [MEDIUM] CWE-400 xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
A flaw was found in xnio. A file descriptor leak caused by growing amounts of NIO Selector file, handled between garbage collection cycles, may allow the attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.
Package: xnio (A-MQ Clients 2) - Not affected
Package: xnio (Red Hat BPM Suite 6) - Out of support scope
Package: xnio (Red Hat Data Grid 8) - Not affected
Package
Debian
CVE-2020-14340: jboss-xnio - A vulnerability was discovered in XNIO where file descriptor leak caused by grow...
vendor_debian·2020·CVSS 5.9
CVE-2020-14340 [MEDIUM] CVE-2020-14340: jboss-xnio - A vulnerability was discovered in XNIO where file descriptor leak caused by grow...
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
Scope: local
bookworm: resolved (fixed in 3.8.2-1)
bullseye: resolved (fixed in 3.8.2-1)
forky: resolved (fixed in 3.8.2-1)
sid: resolved (fixed in 3.8.2-1)
trixie: resolved (fixed in 3.8.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14340 xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
bugzilla·2020-07-24·CVSS 5.9
CVE-2020-14340 [MEDIUM] CVE-2020-14340 xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
CVE-2020-14340 xnio: file descriptor leak caused by growing amounts of NIO Selector file handles may lead to DoS
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service.
It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Enterprise Application Platform 5
* Red Hat JBoss Enterprise Application Platform 6
* Red Hat JBoss Data Grid 6
* Red Hat JBoss Data Grid 7
* Red Hat JBoss Fuse 6
* Red Hat JBoss BRMS 5
* Red Hat JBoss BRMS 6
* Red Hat JBoss Data Virtualization 6
* Red Hat JBoss Operations Network 3
* Red Hat JBoss SOA P
Bugzilla
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14340 [HIGH] CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
It was found that dissectors that support zlib decompression could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14675
External References:
https://www.wireshark.org/security/wnpa-sec-2018-36.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27561/2/epan/tvbuff_zlib.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further
https://bugzilla.redhat.com/show_bug.cgi?id=1860218https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1860218https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-06-02
Published