Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3862
HistoryDec 30, 2010 - 12:00 a.m.

CVE-2010-3862

2010-12-3000:00:00
ubuntu.com
ubuntu.com
18

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.036

Percentile

91.6%

The
org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run
method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2
in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP)
4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka
JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon
outage) by establishing a bisocket control connection TCP session, and then
not sending any application data.

Bugs

Notes

Author Note
mdeslaur debian says not affected, need to check.

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

EPSS

0.036

Percentile

91.6%