Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1336

Опубликовано: 02 авг. 2018
Источник: debian

Описание

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat9not-affectedpackage
tomcat8fixed8.5.31-1package
tomcat8.0removedpackage
tomcat7fixed7.0.72-3package
tomcat7fixed7.0.56-3+really7.0.88-1jessiepackage

Примечания

  • tomcat8.0 builds only tomcat8.0-user and libtomcat8.0-java

  • Since 7.0.72-3, src:tomcat7 only builds the Servlet API

  • https://svn.apache.org/r1830373 (9.0.x)

  • https://svn.apache.org/r1830374 (8.5.x)

  • https://svn.apache.org/r1830375 (8.0.x)

  • https://svn.apache.org/r1830376 (7.0.x)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
redhat
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
nvd
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
github
почти 7 лет назад

In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder

oracle-oval
почти 7 лет назад

ELSA-2018-2921: tomcat security update (IMPORTANT)