Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6817

Опубликовано: 22 нояб. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Toolset 3.1devtoolset-3-tomcatUnder investigation
Red Hat JBoss Enterprise Application Platform 5tomcatNot affected
Red Hat JBoss Enterprise Application Platform 6tomcatNot affected
Red Hat JBoss Enterprise Application Platform 7tomcatNot affected
Red Hat JBoss Enterprise Web Server 2tomcatNot affected
Red Hat JBoss Enterprise Web Server 3tomcatNot affected
Red Hat JBoss Web Server 3tomcat8Not affected
Red Hat Software Collectionsrh-java-common-tomcatUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1397474tomcat: Infinite loop in HTTP/2 header parser

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

CVSS3: 7.5
nvd
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

CVSS3: 7.5
debian
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8. ...

CVSS3: 7.5
github
около 3 лет назад

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3

5 Medium

CVSS2