Back to bug 2229295

Who When What Removed Added
Pedro Sampaio 2023-08-04 19:28:57 UTC Blocks 2229296
Nick Tait 2023-08-05 16:29:28 UTC CC dfreiber, rogbas, vkumar
Patrick Del Bello 2023-08-09 16:13:43 UTC Doc Text A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. A malicious user could start processing a malformed file and with that the server may face a Denial of Service (DoS) attack.
Patrick Del Bello 2023-08-11 19:34:58 UTC Alias TRIAGE-CVE-2023-3635 CVE-2023-3635
Summary TRIAGE-CVE-2023-3635 okio: GzipSource class improper exception handling CVE-2023-3635 okio: GzipSource class improper exception handling
Paige Jung 2023-08-11 20:22:27 UTC Doc Text A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. A malicious user could start processing a malformed file and with that the server may face a Denial of Service (DoS) attack. A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This issue may allow a malicious user to start processing a malformed file, which can result in a Denial of Service (DoS).

Back to bug 2229295