[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2020-1409 --- tomcat8

ID: oval:org.secpod.oval:def:1601176Date: (C)2020-07-31   (M)2024-05-06
Class: PATCHFamily: unix




The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service

Platform:
Amazon Linux AMI
Product:
tomcat8
Reference:
ALAS-2020-1409
CVE-2020-13934
CVE-2020-13935
CVE    2
CVE-2020-13935
CVE-2020-13934

© SecPod Technologies