CVE-2021-41973

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41973
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41973.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-41973
Aliases
Published
2021-11-01T09:15:09Z
Modified
2024-12-26T13:49:02.167404Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

References

Affected packages

Debian:11 / mina

Package

Name
mina
Purl
pkg:deb/debian/mina?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.7.dfsg-13
1.1.7.dfsg-14

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mina

Package

Name
mina
Purl
pkg:deb/debian/mina?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.7.dfsg-13
1.1.7.dfsg-14

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mina

Package

Name
mina
Purl
pkg:deb/debian/mina?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.7.dfsg-13
1.1.7.dfsg-14

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / mina2

Package

Name
mina2
Purl
pkg:deb/debian/mina2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.1.4-2
2.1.5-1
2.1.6-1
2.2.1-1
2.2.1-2
2.2.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mina2

Package

Name
mina2
Purl
pkg:deb/debian/mina2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mina2

Package

Name
mina2
Purl
pkg:deb/debian/mina2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/apache/mina

Affected ranges

Type
GIT
Repo
https://github.com/apache/mina
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.8
2.0.9