Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
|
Information
Published : 2018-04-26 14:29
Updated : 2022-06-29 12:15
NVD link : CVE-2018-10237
Mitre link : CVE-2018-10237
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
redhat
- satellite_capsule
- enterprise_linux
- openstack
- virtualization
- jboss_enterprise_application_platform
- satellite
- openshift_container_platform
- virtualization_host
oracle
- weblogic_server
- retail_integration_bus
- flexcube_private_banking
- customer_management_and_segmentation_foundation
- flexcube_investor_servicing
- database_server
- retail_xstore_point_of_service
- communications_ip_service_activator
- banking_payments
- guava