CVE-2023-3635 - Denial of Service (DoS)

Severity: Low2023-10-05

Abstract

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

The Oxygen products incorporate Okio as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen Content Fusion v8.1 and olderNone Oxygen Content Fusion 8.2 build 2025082116
Oxygen Feedback v4.1 and olderLow Oxygen Feedback 5.0 build 2024111418

Mitigation

None

Detail

CVE-2023-3635

Severity: High

CVSS Score: 7.5

The Okio third-party library used by Oxygen XML products is an affected version mentioned in CVE-2023-3635 vulnerability description. However, since user cannot control the GZIP archive, this vulnerability does not affect Oxygen XML products.

Starting with Oxygen Feedback v5.0, we fixed the vulnerability by updating the affected library to a version that is not vulnerable to CVE-2023-3635.

Starting with Oxygen Content Fusion v8.2, we fixed the vulnerability by updating the affected library to a version that is not vulnerable to CVE-2023-3635.