← Back

CVE-2018-1336

nvd nist
Published: Aug 2, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Affected (44)

Products: Apache: Tomcat · Canonical: Ubuntu Linux · Debian: Debian Linux · +1 more
Show all products
1 product
Tomcat
1 product
Ubuntu Linux
1 product
Debian Linux
5 products
Jboss Enterprise Web Server
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Workstation
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 7.0.28 to 7.0.86
From 8.0.0 to 8.0.51
From 8.5.0 to 8.5.30
From 9.0.1 to 9.0.7
Version 8.0.0 rc10
Version 8.0.0 rc1
Version 8.0.0 rc2
Version 8.0.0 rc3
Version 8.0.0 rc4
Version 8.0.0 rc5
Version 8.0.0 rc6
Version 8.0.0 rc7
Version 8.0.0 rc8
Version 8.0.0 rc9
Version 9.0.0 milestone10
Version 9.0.0 milestone11
Version 9.0.0 milestone12
Version 9.0.0 milestone13
Version 9.0.0 milestone14
Version 9.0.0 milestone15
Version 9.0.0 milestone16
Version 9.0.0 milestone17
Version 9.0.0 milestone18
Version 9.0.0 milestone19
Version 9.0.0 milestone20
Version 9.0.0 milestone21
Version 9.0.0 milestone22
Version 9.0.0 milestone23
Version 9.0.0 milestone24
Version 9.0.0 milestone25
Version 9.0.0 milestone26
Version 9.0.0 milestone27
Version 9.0.0 milestone9
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Debian
Version 8.0
Version 9.0
Redhat
Version 6.0.0
Version 6.4.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 5.0.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Redhat
Enterprise Linux
Version 7.0
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Version 7.0
Version 7.0

References (76)

Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.