Lucene search

K
freebsdFreeBSD134ACAA2-51EF-11E2-8E34-0022156E8794
HistoryDec 04, 2012 - 12:00 a.m.

tomcat -- denial of service

2012-12-0400:00:00
vuxml.freebsd.org
19

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

0.705 High

EPSS

Percentile

98.1%

The Apache Software Foundation reports:

When using the NIO connector with sendfile and HTTPS enabled, if a
client breaks the connection while reading the response an infinite loop
is entered leading to a denial of service.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchtomcat= 6.0.0UNKNOWN
FreeBSDanynoarchtomcat<= 6.0.35UNKNOWN
FreeBSDanynoarchtomcat7= 7.0.0UNKNOWN
FreeBSDanynoarchtomcat7<= 7.0.27UNKNOWN

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

0.705 High

EPSS

Percentile

98.1%