A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3E | Mailing List Vendor Advisory |
| https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f@%3Cusers.mina.apache.org%3E | Mailing List Vendor Advisory |
| https://lists.apache.org/thread.html/red01829efa2a8c893c4baff4f23c9312bd938543a9b8658e172b853b@%3Cannounce.apache.org%3E | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2021/07/12/1 | Mailing List Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2021-07-12 12:15
Updated : 2022-07-25 18:15
NVD link : CVE-2021-30129
Mitre link : CVE-2021-30129
JSON object : View
Products Affected
oracle
- middleware_common_libraries_and_tools
- oss_support_tools
- banking_trade_finance
- banking_treasury_management
- retail_customer_management_and_segmentation_foundation
- flexcube_universal_banking
- banking_payments
- communications_cloud_native_core_console
apache
- sshd
CWE
CWE-772
Missing Release of Resource after Effective Lifetime
