Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3596
HistoryFeb 22, 2017 - 2:23 a.m.

Denial Of Service (DoS) Via Infinite Loop

2017-02-2202:23:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.013 Low

EPSS

Percentile

86.2%

tomcat-coyote is vulnerable to denial of service (DoS) attacks. The vulnerability is a result of backporting a fix for CVE-2016-6816 but not backporting the fix for the Tomcat bug 57544 which fails to handle an exceptional condition check for pos while processing HTTPS requests in the Apache Tomcat servlet and JSP engine.

References