Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m59c-jpc8-m2x4

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Ссылки

Пакеты

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.0.M9, <= 9.0.7

9.0.8

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.5.0, < 8.5.31

8.5.31

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.0.0RC1, < 8.0.51

8.0.51

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 7.0.28, < 7.0.87

7.0.87

EPSS

Процентиль: 88%
0.0393
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
redhat
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
nvd
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

CVSS3: 7.5
debian
около 7 лет назад

An improper handing of overflow in the UTF-8 decoder with supplementar ...

oracle-oval
почти 7 лет назад

ELSA-2018-2921: tomcat security update (IMPORTANT)

EPSS

Процентиль: 88%
0.0393
Низкий

7.5 High

CVSS3

Дефекты

CWE-835