Lucene search

K
githubGitHub Advisory DatabaseGHSA-M59C-JPC8-M2X4
HistoryOct 17, 2018 - 4:32 p.m.

In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder

2018-10-1716:32:18
CWE-835
GitHub Advisory Database
github.com
21

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.021

Percentile

89.2%

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Affected configurations

Vulners
Node
org.apache.tomcat.embedtomcat-embed-coreRange8.0.0RC18.0.51
OR
org.apache.tomcat.embedtomcat-embed-coreRange9.0.0.M99.0.7
OR
org.apache.tomcat.embedtomcat-embed-coreRange7.0.287.0.87
OR
org.apache.tomcat.embedtomcat-embed-coreRange8.5.08.5.31
VendorProductVersionCPE
org.apache.tomcat.embedtomcat-embed-core*cpe:2.3:a:org.apache.tomcat.embed:tomcat-embed-core:*:*:*:*:*:*:*:*

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.021

Percentile

89.2%