ZeroHour

CVE-2018-1336

CVSS 3.1
7.5 high
EPSS
21%p97
Published
()
Modified
Description

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Vendors
apacheredhatcanonicaldebian
Products
tomcat, jboss enterprise application platform, ubuntu linux, debian linux, jboss enterprise web server, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news