GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
2023-07-12T19:15:08.983
2024-11-21T08:17:43.213
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | squareup | okio | < 1.17.6 | Yes |
Application | squareup | okio | < 3.4.0 | Yes |