{"id":"GHSA-9959-6p3m-wxpc","summary":"Denial of service in Netty","details":"The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.","aliases":["CVE-2014-3488"],"modified":"2023-11-08T03:57:37.697735Z","published":"2020-06-30T21:01:31Z","database_specific":{"github_reviewed_at":"2020-06-30T20:50:42Z","nvd_published_at":null,"cwe_ids":["CWE-119"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3488"},{"type":"WEB","url":"https://github.com/netty/netty/issues/2562"},{"type":"WEB","url":"https://github.com/netty/netty/commit/2fa9400a59d0563a66908aba55c41e7285a04994"},{"type":"PACKAGE","url":"https://github.com/netty/netty"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGJBOSSNETTY-31630"},{"type":"WEB","url":"http://netty.io/news/2014/06/11/3-9-2-Final.html"},{"type":"WEB","url":"http://secunia.com/advisories/59196"}],"affected":[{"package":{"name":"io.netty:netty-handler","ecosystem":"Maven","purl":"pkg:maven/io.netty/netty-handler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-9959-6p3m-wxpc/GHSA-9959-6p3m-wxpc.json"}}],"schema_version":"1.9.0"}