Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6808

Опубликовано: 06 окт. 2016
Источник: redhat
CVSS3: 8.1
CVSS2: 6.8
EPSS Средний

Описание

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

It was found that the length checks prior to writing to the target buffer for creating a virtual host mapping rule did not take account of the length of the virtual host name, creating the potential for a buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 5mod_jkUnder investigation
Red Hat JBoss Enterprise Application Platform 6mod_jkAffected
Red Hat JBoss Enterprise Web Server 1mod_jkUnder investigation
Red Hat JBoss Enterprise Web Server 2mod_jkAffected
Red Hat JBoss Enterprise Web Server 3mod_jkAffected
Red Hat JBoss Web Server 3mod_jkAffected
JBoss Core Services on RHEL 6jbcs-httpd24-httpdFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_auth_kerbFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_bmxFixedRHSA-2017:019325.01.2017
JBoss Core Services on RHEL 6jbcs-httpd24-mod_cluster-nativeFixedRHSA-2017:019325.01.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1382352mod_jk: Buffer overflow when concatenating virtual host name and URI

EPSS

Процентиль: 97%
0.34234
Средний

8.1 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

CVSS3: 9.8
nvd
почти 9 лет назад

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

CVSS3: 9.8
debian
почти 9 лет назад

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

CVSS3: 9.8
github
больше 3 лет назад

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

EPSS

Процентиль: 97%
0.34234
Средний

8.1 High

CVSS3

6.8 Medium

CVSS2