Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4610

Опубликовано: 31 янв. 2012
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tomcat5Not affected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss Enterprise Web Server 1tomcat5Not affected
Red Hat JBoss Enterprise Web Server 1tomcat6Not affected
JBEWP 5 for RHEL 5jbosswebFixedRHSA-2012:007631.01.2012
JBEWP 5 for RHEL 6jbosswebFixedRHSA-2012:007631.01.2012
JBoss Communications Platform 5.1FixedRHSA-2012:007831.01.2012
JBoss Enterprise BRMS Platform 5.1FixedRHSA-2012:032522.02.2012
Red Hat JBoss Enterprise Application Platform 5.1FixedRHSA-2012:007531.01.2012

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=767871JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary

EPSS

Процентиль: 81%
0.01496
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

debian
почти 12 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1 ...

github
больше 3 лет назад

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

EPSS

Процентиль: 81%
0.01496
Низкий

5 Medium

CVSS2