The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
{
"unresolved_ranges": [
{
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "33"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:communications_brm_-_elastic_charging_engine",
"cpes": [
"cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "12.0.0.3"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:communications_cloud_native_core_service_communication_proxy",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.5.2:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "1.5.2"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:communications_design_studio",
"cpes": [
"cpe:2.3:a:oracle:communications_design_studio:7.4.2:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "7.4.2"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:communications_messaging_server",
"cpes": [
"cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.1"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:nosql_database",
"cpes": [
"cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "20.3"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:siebel_core_-_server_framework",
"cpes": [
"cpe:2.3:a:oracle:siebel_core_-_server_framework:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "21.5"
}
],
"source": "CPE_FIELD"
},
{
"vendor_product": "oracle:webcenter_portal",
"cpes": [
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"source": "CPE_FIELD"
}
]
}