CVE-2014-3488: Buffer Overflow
Netty is vulnerable to a denial of service, caused by an error in SslHandler. A remote attacker could exploit this vulnerability using a specially-crafted SSLv2Hello message to exhaust all available CPU resources and cause the application to enter into an infinite loop.
Other sources
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Netty vulnerability?
The vulnerability ID for this Netty vulnerability is CVE-2014-3488.
What is the severity rating of CVE-2014-3488?
The severity rating of CVE-2014-3488 is medium.
How does this vulnerability affect Netty?
This vulnerability in Netty can cause a denial of service by exhausting CPU resources.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability using a specially-crafted SSLv2Hello message.
Is there a fix available for CVE-2014-3488?
Yes, there are fixes available for CVE-2014-3488. Please refer to the provided reference for more information.