Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3635


GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.


Published

2023-07-12T19:15:08.983

Last Modified

2024-11-21T08:17:43.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-195
  • Type: Primary
    CWE-681

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application squareup okio < 1.17.6 Yes
Application squareup okio < 3.4.0 Yes

References