Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 821250 (CVE-2021-41973) - dev-java/mina-core: infinite loop vulnerability (CVE-2021-41973)
Summary: dev-java/mina-core: infinite loop vulnerability (CVE-2021-41973)
Status: RESOLVED FIXED
Alias: CVE-2021-41973
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2021-11-01 19:13 UTC by John Helmert III
Modified: 2022-08-16 19:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-11-01 19:13:52 UTC
CVE-2021-41973:

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

Fixed in 2.0.22 and 2.1.5, please bump.
Comment 1 Larry the Git Cow gentoo-dev 2021-12-06 07:31:24 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=445c3eb6a0ea653fc5c82129b74ee2c15c753699

commit 445c3eb6a0ea653fc5c82129b74ee2c15c753699
Author:     Jakov Smolić <jsmolic@gentoo.org>
AuthorDate: 2021-12-06 07:29:33 +0000
Commit:     Jakov Smolić <jsmolic@gentoo.org>
CommitDate: 2021-12-06 07:29:37 +0000

    dev-java/mina-core: treeclean
    
    Bug: https://bugs.gentoo.org/821250
    Signed-off-by: Jakov Smolić <jsmolic@gentoo.org>

 dev-java/mina-core/Manifest                  |  2 --
 dev-java/mina-core/metadata.xml              |  8 ------
 dev-java/mina-core/mina-core-1.1.7-r1.ebuild | 29 ---------------------
 dev-java/mina-core/mina-core-2.0.7-r1.ebuild | 39 ----------------------------
 profiles/package.mask                        |  4 ---
 5 files changed, 82 deletions(-)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-16 19:50:46 UTC
Only an infinite loop, no glsa.