CVE-2021-41973Infinite Loop in Software Foundation Apache Mina

CWE-835Infinite Loop9 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 25.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateApr 15

Description

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages10 packages

NVDapache/mina2.1.02.1.5+1
CVEListV5apache_software_foundation/apache_minaApache MINA2.1.5

Patches

🔴Vulnerability Details

4
OSV
Infinite loop in Apache MINA2021-11-03
GHSA
Infinite loop in Apache MINA2021-11-03
OSV
CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely2021-11-01
CVEList
Apache MINA HTTP listener DOS2021-11-01

📋Vendor Advisories

4
Oracle
Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina) — CVE-2021-419732023-04-15
Oracle
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) — CVE-2021-419732022-04-15
Red Hat
mina-core: infinite loop may lead to DoS2021-11-01
Debian
CVE-2021-41973: mina - In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTT...2021
CVE-2021-41973 — Infinite Loop | cvebase