Skip to content
AppleGHSA-xhhr-p2r9-jmm7

Request/response decompression checks the size of compressed instead of decompressed bytes

HighCVE-2020-9840 · Published May 2, 2020

### Impact When using the `.size` decompression limit, request & response decompression checks the size of _compressed_ instead of _decompressed_ bytes which allows to remotely cause a denial-of-service in a client/server. ### Patches Released on `swift-nio-extras` version 1.4.1. ### Workarounds Use the `.ratio` decompression limit. ### Thanks Many thanks to @adtrevor for the bug report & fix.

GitHub advisory

Affected versions

PackageAffectedFixed in
swift-nio-extras
Product
< 1.4.11.4.1
Details and references

More Apple advisories

All Apple
Advisory
HTTP request smuggling using malformed Transfer-Encoding header
CriticalFeb 17, 2020
Executable Stack
MediumNov 25, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.