Описание
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat JBoss BRMS 5 | jbossweb | Not affected | ||
Red Hat JBoss Data Grid 6 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | eap5 | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | eap6 | Not affected | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat7 | Not affected | ||
Red Hat JBoss Operations Network 3.1 | jbossweb | Not affected | ||
Red Hat JBoss Portal 5 | jbossweb | Not affected | ||
Red Hat JBoss SOA Platform 5 | jbossweb | Not affected | ||
Red Hat Enterprise Linux 6 | tomcat6 | Fixed | RHSA-2013:0623 | 11.03.2013 |
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat6 | Fixed | RHSA-2013:0266 | 19.02.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x befor ...
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
EPSS
4.3 Medium
CVSS2