CVE Database
/

CVE-2018-1336

Back to search

CVE-2018-1336

Published: Aug 2, 2018

Modified: Nov 14, 2024

PUBLISHED

Description

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M9 to 9.0.7
affected
8.5.0 to 8.5.30
affected
8.0.0.RC1 to 8.0.51
affected
7.0.28 to 7.0.86

References

USN-3723-1
vendor-advisory
x_refsource_UBUNTU
104898
vdb-entry
x_refsource_BID
RHSA-2018:2740
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2741
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2921
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2742
vendor-advisory
x_refsource_REDHAT
DSA-4281
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:2945
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2939
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2701
vendor-advisory
x_refsource_REDHAT
RHEA-2018:2188
vendor-advisory
x_refsource_REDHAT
RHEA-2018:2189
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2743
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2700
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3768
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2930
vendor-advisory
x_refsource_REDHAT
1041375
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now