← back
CVE-2021-37136

CVE-2021-37136

EPSS 5.7%CWE-400
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 5.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
19 Oct 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →