MEDIUM🇵🇱 Wersja polska

CVE-2023-3635

CVSS 5.9v3.1pub. 2023-07-12upd. 2024-11-21

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Squareup Okio

    APP
    Squareup
    0.5.0 – 1.17.6 (excl.)2.0.0 – 3.4.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2018-1000844CRITICAL9.1PL ✓same vendor

XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF

CVE-2015-8969CRITICAL9.8PL ✓same vendor

Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń

CVE-2026-45799HIGH7.5PL ✓same vendor

Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi

CVE-2018-1000850HIGH7.5same vendor

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vul...

CVE-2015-8968HIGH8.8same vendor

git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can inst...