Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8 MGASA-2021-0136 Moderate: Netty Multipart Decoders Threat

mageia
Calendar Grey March 14, 2021
Dist Mageia Esm H88
Revised netty libraries for Mageia 8 tackle a severe data exposure flaw on localized environments.
When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled (CVE-20...

Summary

When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled (CVE-2021-21290).

References

- https://bugs.mageia.org/show_bug.cgi?id=28446

- https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2

- https://www.cve.org/CVERecord?id=CVE-2021-21290

Resolution

SRPMS

- 8/core/netty-4.1.51-1.1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 14 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0136.html
Type: security
CVE: CVE-2021-21290

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here