CVE-2014-3488

Related Vulnerabilities: CVE-2014-3488  

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

The MITRE CVE dictionary describes this issue as:

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

Find out more about CVE-2014-3488 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Netty versions as shipped by Red Hat products are not affected by this flaw.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 7.8
Base Metrics AV:N/AC:L/Au:N/C:N/I:N/A:C
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 netty Not affected
Red Hat Software Collections 1 for Red Hat Enterprise Linux thermostat1-netty Not affected
Red Hat Satellite 6 netty Not affected
Red Hat JBoss Portal Platform 6 netty Not affected
Red Hat JBoss Portal 5 netty Not affected
Red Hat JBoss Fuse Service Works 6 netty Not affected
Red Hat JBoss EAP 6 netty Not affected
Red Hat JBoss EAP 5 netty Not affected
Red Hat JBoss BRMS 6 netty Not affected
Red Hat JBoss BPMS 6 netty Not affected

Acknowledgements

Red Hat would like to thank Laurentiu Luca for reporting this issue.