Описание
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Меры по смягчению последствий
pki-servlet-container does not use HTTP/2 in its default configuration.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat BPM Suite 6 | tomcat | Out of support scope | ||
Red Hat Enterprise Linux 6 | tomcat | Not affected | ||
Red Hat Enterprise Linux 7 | tomcat | Not affected | ||
Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-container | Will not fix | ||
Red Hat Fuse 7 | tomcat | Not affected | ||
Red Hat JBoss BRMS 6 | tomcat | Out of support scope | ||
Red Hat JBoss Data Grid 7 | tomcat | Not affected | ||
Red Hat JBoss Fuse 6 | tomcat | Not affected | ||
Red Hat JBoss Web Server 5 | tomcat | Fixed | RHSA-2019:3931 | 20.11.2019 |
Red Hat JBoss Web Server 5.2 on RHEL 6 | jws5-ecj | Fixed | RHSA-2019:3929 | 20.11.2019 |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 co ...
Уязвимость сервера приложений Apache Tomcat, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
5.3 Medium
CVSS3