ZeroHour

CVE-2018-1041

PoC
CVSS 3.0
7.5 high
EPSS
16%p97
Published
()
Modified
Description

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Vendors
jbossredhat
Products
jboss-remoting, jboss enterprise application platform
Weakness
CWE-835
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.