Описание
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 8.5.39-1ubuntu1~18.04.3 |
cosmic | ignored | end of life |
devel | DNE | |
disco | DNE | |
esm-apps/bionic | released | 8.5.39-1ubuntu1~18.04.3 |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | not-affected | code not present |
precise/esm | DNE | |
trusty | ignored | end of standard support |
trusty/esm | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 9.0.16-3ubuntu0.18.04.1 |
cosmic | ignored | end of life |
devel | not-affected | 9.0.20 |
disco | released | 9.0.16-3ubuntu0.19.04.1 |
esm-apps/bionic | released | 9.0.16-3ubuntu0.18.04.1 |
esm-infra-legacy/trusty | DNE | |
precise/esm | DNE | |
trusty | ignored | end of standard support |
trusty/esm | DNE | |
upstream | released | 9.0.20 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 co ...
Уязвимость сервера приложений Apache Tomcat, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2
7.5 High
CVSS3