handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netty | Netty | 4.0.20 (including) | 4.0.37 (excluding) |
Netty | Netty | 4.1.0 (including) | 4.1.1 (excluding) |
Red Hat Fuse 7.7.0 | RedHat | netty | * |
Red Hat JBoss A-MQ 6.3 | RedHat | * | |
Red Hat JBoss Data Grid 7.1 | RedHat | * | |
Red Hat JBoss Fuse 6.3 | RedHat | * | |
Netty | Ubuntu | esm-apps/xenial | * |
Netty | Ubuntu | upstream | * |
Netty | Ubuntu | xenial | * |