Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1041

Опубликовано: 05 фев. 2018
Источник: redhat
CVSS3: 4.3
EPSS Средний

Описание

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10.Final-redhat-1, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7jboss-remotingNot affected
Red Hat JBoss Enterprise Application Platform 6.4jboss-remotingFixedRHSA-2018:026905.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5hornetqFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5infinispanFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5ironjacamar-eap6FixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-appclientFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-appclientFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-bundlesFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-cliFixedRHSA-2018:027105.02.2018
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-client-allFixedRHSA-2018:027105.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1530457jboss-remoting: High CPU Denial of Service

EPSS

Процентиль: 94%
0.14129
Средний

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

CVSS3: 7.5
nvd
почти 8 лет назад

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

CVSS3: 7.5
debian
почти 8 лет назад

A vulnerability was found in the way RemoteMessageChannel, introduced ...

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

EPSS

Процентиль: 94%
0.14129
Средний

4.3 Medium

CVSS3