Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 06 Jan 2022 17:48:38 +0000
From: Ryan Skraba <>
Subject: CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C#
 Avro SDK 


A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack.  This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions.  Users should update to version 1.11.0 which addresses this issue.

This issue is being tracked as AVRO-3225,AVRO-3226


Apache Avro would like to thank Philip Sanetra for reporting this issue.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.