CVE-2021-37136 - Denial of Service (DoS)

Severity: Low2021-12-08

Security Advisories

Abstract

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack.

The Oxygen XML products incorporates the Netty as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen Content Fusion 4.1 and olderLow Oxygen Content Fusion 5.0 build 2022092005

Mitigation

None

Detail

CVE-2021-37136

Severity: High

CVSS Score: 7.5

The Netty third-party library used by Oxygen XML software products is an affected version mentioned in CVE-2021-37136 vulnerability description. However, the Oxygen XML software products doesn't use Netty to decompress user-supplied Bzip2 data streams. Therefore Oxygen XML software products are not impacted by CVE-2021-37136.

Revision History

2022-10-13 Starting with Oxygen Content Fusion version 5.0 build 2022092005, the Netty library was updated to version 4.1.78, which includes a fix for CVE-2021-37136.

List of Security Advisories