Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian DSA-4885-1 Critical: Netty Issues With HTTP Smuggling and DoS

debian
Calendar Grey April 5, 2021
Debian Logo
Several vulnerabilities in Netty may result in HTTP smuggling, Denial of Service (DoS), or exposure of sensitive data. Debian users are advised to perform an upgrade.
Multiple security issues were discovered in Netty, a Java NIO client/server framework, which could result in HTTP request smuggling, denial of service or information disclosure

Summary

Multiple security issues were discovered in Netty, a Java NIO
client/server framework, which could result in HTTP request smuggling,
denial of service or information disclosure.

For the stable distribution (buster), these problems have been fixed in
version 1:4.1.33-1+deb10u2.

We recommend that you upgrade your netty packages.

For the detailed security status of netty please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/netty

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: netty
CVE ID: CVE-2019-20444 CVE-2019-20445 CVE-2020-7238 CVE-2020-11612

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here