1040323vdb entry
http://www.securitytracker.com/id/1040323 CVE-2018-1041
HIGH
JBoss Remoting 6.14.18 - Denial of Service
Record summary
CVE-2018-1041 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jboss-remotingBrowse Red Hat, Inc. / jboss-remoting | CVE List | since 3.3.10 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBJBoss Remoting 6.14.18 - Denial of ServiceExploitDB exploitby Frank SpieringsNot analyzed1 file
References
9RHSA-2018:0268Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0268 RHSA-2018:0269Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0269 RHSA-2018:0270Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0270 RHSA-2018:0271Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0271 RHSA-2018:0275Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0275 bugzilla.redhat.comConfirmation
https://bugzilla.redhat.com/show_bug.cgi?id=1530457 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1041 44099exploit
https://www.exploit-db.com/exploits/44099