Record summary

CVE-2018-1041 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listsince 3.3.10affected

Proofs of concept

1

Catalogued exploits

ExploitDBJBoss Remoting 6.14.18 - Denial of ServiceExploitDB exploitby Frank SpieringsNot analyzed1 file
ExploitDB

PoC details

References

9