Netty 拒绝服务漏洞

漏洞信息详情

Netty 拒绝服务漏洞

漏洞简介

Netty是Netty项目社区的一个提供了异步的、事件驱动的Java网络应用程序框架和工具,它用以快速开发高性能、高可靠性的网络服务器和客户端程序。

Netty 3.9.2之前版本的SslHandler中存在安全漏洞。远程攻击者可通过发送特制的‘SSLv2Hello’消息利用该漏洞造成拒绝服务(无限循环和CPU资源耗尽)。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

http://netty.io/news/2014/06/11/3-9-2-Final.html

参考网址

来源:CONFIRM

链接:https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994

来源:SECUNIA

链接:http://secunia.com/advisories/59196

来源:CONFIRM

链接:http://netty.io/news/2014/06/11/3-9-2-Final.html

来源:CONFIRM

链接:https://github.com/netty/netty/issues/2562

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html

来源:lists.debian.org

链接:https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Netty-overload-via-SSLv2Hello-SslHandler-31648

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dependent-libraries-affect-ibm-db2-leading-to-denial-of-service-or-privilege-escalation-3/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dependent-libraries-affect-ibm-db2-leading-to-denial-of-service-or-privilege-escalation-2/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-have-been-identified-in-db2-that-affect-the-ibm-performance-management-product/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.0583/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dependent-libraries-affect-ibm-db2-leading-to-denial-of-service-or-privilege-escalation/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1427/

来源:www.ibm.com

链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-warehouse-has-released-a-fix-in-response-to-multiple-vulnerabilities-found-in-ibm-db2/

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享