Уязвимость CVE-2019-0199: Информация
Описание
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Важность: HIGH (7,5) Вектор: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Исправленные пакеты
Имя пакета | Ветка | Исправлено в версии | Версия в репозитории | Errata ID | № Задания | Состояние |
---|---|---|---|---|---|---|
tomcat | sisyphus | 9.0.37-alt1 | 9.0.83-alt1_1jpp11 | ALT-PU-2020-2892-1 | 255548 | Исправлено |
tomcat | p10 | 9.0.37-alt1 | 9.0.59-alt1_3jpp11 | ALT-PU-2020-2892-1 | 255548 | Исправлено |
tomcat | p9 | 9.0.37-alt1 | 9.0.37-alt1 | ALT-PU-2020-3213-2 | 258915 | Исправлено |
tomcat | c10f1 | 9.0.37-alt1 | 9.0.59-alt1_3jpp11 | ALT-PU-2020-2892-1 | 255548 | Исправлено |
tomcat | c9f2 | 9.0.37-alt0.c9.1 | 9.0.37-alt0.c9.1 | ALT-PU-2021-2858-2 | 282600 | Исправлено |
tomcat | p11 | 9.0.37-alt1 | 9.0.83-alt1_1jpp11 | ALT-PU-2020-2892-1 | 255548 | Исправлено |