Bug 2229295 (CVE-2023-3635) - CVE-2023-3635 okio: GzipSource class improper exception handling
Summary: CVE-2023-3635 okio: GzipSource class improper exception handling
Keywords:
Status: NEW
Alias: CVE-2023-3635
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2229296
TreeView+ depends on / blocked
 
Reported: 2023-08-04 19:27 UTC by Pedro Sampaio
Modified: 2024-05-28 11:20 UTC (History)
77 users (show)

Fixed In Version: okio 3.4.0, okio 3.5.0
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This issue may allow a malicious user to start processing a malformed file, which can result in a Denial of Service (DoS).
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:5165 0 None None None 2023-09-14 09:51:58 UTC
Red Hat Product Errata RHSA-2023:7247 0 None None None 2023-11-15 17:07:56 UTC
Red Hat Product Errata RHSA-2024:1353 0 None None None 2024-03-18 09:48:28 UTC
Red Hat Product Errata RHSA-2024:3385 0 None None None 2024-05-28 11:20:00 UTC

Description Pedro Sampaio 2023-08-04 19:27:10 UTC
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

References:

https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b
https://research.jfrog.com/vulnerabilities/okio-gzip-source-unhandled-exception-dos-xray-523195/

Comment 10 errata-xmlrpc 2023-09-14 09:51:53 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.5.0

Via RHSA-2023:5165 https://access.redhat.com/errata/RHSA-2023:5165

Comment 12 errata-xmlrpc 2023-11-15 17:07:52 UTC
This issue has been addressed in the following products:

  Red Hat Fuse 7.12.1

Via RHSA-2023:7247 https://access.redhat.com/errata/RHSA-2023:7247

Comment 15 errata-xmlrpc 2024-03-18 09:48:24 UTC
This issue has been addressed in the following products:

  RHPAM 7.13.5 async

Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353

Comment 16 errata-xmlrpc 2024-05-28 11:19:55 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2024:3385 https://access.redhat.com/errata/RHSA-2024:3385


Note You need to log in before you can comment on or make changes to this bug.