Candidate: CVE-2016-4970 PublicDate: 2017-04-13 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4970 Description: handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). Ubuntu-Description: Notes: seth-arnold> Users can use -Djdk.tls.rejectClientInitiatedRenegotiation=true to disable renegotiation and avoid this issue. seth-arnold> Versions affected: Netty 4.0.0.Final - 4.0.36.Final and 4.1.0.Final Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=827620 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-4970 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_netty: upstream_netty: released (1:4.0.37-1) precise_netty: not-affected precise/esm_netty: DNE (precise was not-affected) trusty_netty: not-affected trusty/esm_netty: not-affected vivid/stable-phone-overlay_netty: DNE vivid/ubuntu-core_netty: DNE wily_netty: not-affected xenial_netty: ignored (end of standard support, was needed) yakkety_netty: not-affected (1:4.0.37-1) zesty_netty: not-affected (1:4.0.37-1) artful_netty: not-affected (1:4.0.37-1) bionic_netty: not-affected (1:4.0.37-1) cosmic_netty: not-affected (1:4.0.37-1) disco_netty: not-affected (1:4.0.37-1) eoan_netty: not-affected (1:4.0.37-1) focal_netty: not-affected (1:4.0.37-1) groovy_netty: not-affected (1:4.0.37-1) hirsute_netty: not-affected (1:4.0.37-1) impish_netty: not-affected (1:4.0.37-1) jammy_netty: not-affected (1:4.0.37-1) devel_netty: not-affected (1:4.0.37-1)