GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HSquareup Okio
APPSquareup0.5.0 – 1.17.6 (bez)2.0.0 – 3.4.0 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
Powiązane podatności
CVE-2018-1000844CRITICAL9.1PL ✓ten sam vendor
XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF
CVE-2015-8969CRITICAL9.8PL ✓ten sam vendor
Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń
CVE-2026-45799HIGH7.5PL ✓ten sam vendor
Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi
CVE-2018-1000850HIGH7.5ten sam vendor
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vul...
CVE-2015-8968HIGH8.8ten sam vendor
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can inst...