CVE-2021-41973
Summary
| CVE | CVE-2021-41973 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-01 09:15:00 UTC |
| Updated | 2022-05-02 18:09:00 UTC |
| Description | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater. |
Risk And Classification
Problem Types: CWE-835
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Mina | All | All | All | All |
| Application | Oracle | Banking Payments | 14.5 | All | All | All |
| Application | Oracle | Banking Trade Finance Process Management | 14.5 | All | All | All |
| Application | Oracle | Banking Treasury Management | 14.5 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Console | 1.9.0 | All | All | All |
| Application | Oracle | Customer Management And Segmentation Foundation | 18.0 | All | All | All |
| Application | Oracle | Customer Management And Segmentation Foundation | 19.0 | All | All | All |
| Application | Oracle | Flexcube Universal Banking | 14.5 | All | All | All |
| Application | Oracle | Flexcube Universal Banking | All | All | All | All |
| Application | Oracle | Fusion Middleware Common Libraries And Tools | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Fusion Middleware Common Libraries And Tools | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Fusion Middleware Common Libraries And Tools | 14.1.1.0.0 | All | All | All |
| Application | Oracle | Oss Support Tools | 2.12.42 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MISC | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| oss-security - CVE-2021-41973: Apache MINA HTTP listener DOS | MLIST | www.openwall.com | |
| oss-security - [ANNOUNCE] Apache MINA 2.0.22 & 2.1.5 released | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980230 Java (maven) Security Update for org.apache.mina:mina-core (GHSA-6mcm-j9cj-3vc3)