CVE Database
/

CVE-2017-6056

Back to search

CVE-2017-6056

Published: Feb 17, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2017:0828
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0827
vendor-advisory
x_refsource_REDHAT
DSA-3787
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:0517
vendor-advisory
x_refsource_REDHAT
DSA-3788
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:0826
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0829
vendor-advisory
x_refsource_REDHAT
96293
vdb-entry
x_refsource_BID
1037860
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now