CVE-2023-3635 - Denial of Service (DoS)
Severity: Low2023-10-05
Abstract
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
The Oxygen products incorporate Okio as a third-party library. This advisory was opened to address the potential impact of this third-party library vulnerability.
Affected Products/Versions
| Product | Severity | Fixed Release Availability |
| Oxygen Content Fusion v8.1 and older | None | Oxygen Content Fusion 8.2 build 2025082116 |
| Oxygen Feedback v4.1 and older | Low | Oxygen Feedback 5.0 build 2024111418 |
Detail
CVE-2023-3635
Severity: High
CVSS Score: 7.5
The Okio third-party library used by Oxygen XML products is an affected version mentioned in CVE-2023-3635 vulnerability description. However, since user cannot control the GZIP archive, this vulnerability does not affect Oxygen XML products.
Starting with Oxygen Feedback v5.0, we fixed the vulnerability by updating the affected library to a version that is not vulnerable to CVE-2023-3635.
Starting with Oxygen Content Fusion v8.2, we fixed the vulnerability by updating the affected library to a version that is not vulnerable to CVE-2023-3635.
