Debian Security Advisory

DLA-2555-1 netty -- LTS security update

Date Reported:
11 Feb 2021
Affected Packages:
netty
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-21290.
More information:

It was discovered that there was an insecure temporary file issue that could have lead to disclosure of arbitrary local files.

  • CVE-2021-21290

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. [...]

For Debian 9 Stretch, these problems have been fixed in version 1:4.1.7-2+deb9u3.

We recommend that you upgrade your netty packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS