CVE-2023-3635
Okio GzipSource unhandled exception Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
GzipSource no maneja una excepción que podría surgir al analizar un búfer gzip malformado. Esto puede conducir a la denegación de servicio del cliente Okio cuando se maneja un archivo GZIP manipulado, mediante el uso de la clase "GzipSource".
A flaw was found in SquareUp Okio. A class GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This issue may allow a malicious user to start processing a malformed file, which can result in a Denial of Service (DoS).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-07-12 CVE Reserved
- 2023-07-12 CVE Published
- 2024-08-13 EPSS Updated
- 2024-10-23 CVE Updated
- 2024-10-23 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-195: Signed to Unsigned Conversion Error
- CWE-248: Uncaught Exception
- CWE-681: Incorrect Conversion between Numeric Types
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://research.jfrog.com/vulnerabilities/okio-gzip-source-unhandled-exception-dos-xray-523195 | 2024-10-23 |
URL | Date | SRC |
---|---|---|
https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b | 2023-10-25 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-3635 | 2024-09-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2229295 | 2024-09-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Squareup Search vendor "Squareup" | Okio Search vendor "Squareup" for product "Okio" | >= 0.5.0 < 1.17.6 Search vendor "Squareup" for product "Okio" and version " >= 0.5.0 < 1.17.6" | - |
Affected
| ||||||
Squareup Search vendor "Squareup" | Okio Search vendor "Squareup" for product "Okio" | >= 2.0.0 < 3.4.0 Search vendor "Squareup" for product "Okio" and version " >= 2.0.0 < 3.4.0" | - |
Affected
|