CVE-2023-3635

NameCVE-2023-3635
DescriptionGzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
okio (PTS)buster1.16.0-1fixed
sid, trixie, bookworm, bullseye1.16.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
okiosource(unstable)(not affected)

Notes

- okio <not-affected> (Doesn't ship Kotlin variant yet)
https://research.jfrog.com/vulnerabilities/okio-gzip-source-unhandled-exception-dos-xray-523195/
https://github.com/square/okio/commit/81bce1a30af244550b0324597720e4799281da7b

Search for package or bug name: Reporting problems