CVE-2017-6056
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 7.49% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2017-0517.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3787Third Party Advisory
- http://www.debian.org/security/2017/dsa-3788Third Party Advisory
- http://www.securityfocus.com/bid/96293Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037860Third Party Advisory, VDB Entry
- https://bugs.debian.org/851304Issue Tracking, Third Party Advisory
- https://bz.apache.org/bugzilla/show_bug.cgi?id=60578Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3E
- https://lists.debian.org/debian-security-announce/2017/msg00038.htmlThird Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00039.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180731-0002/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- http://rhn.redhat.com/errata/RHSA-2017-0517.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3787Third Party Advisory
- http://www.debian.org/security/2017/dsa-3788Third Party Advisory
- http://www.securityfocus.com/bid/96293Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037860Third Party Advisory, VDB Entry
- https://bugs.debian.org/851304Issue Tracking, Third Party Advisory
- https://bz.apache.org/bugzilla/show_bug.cgi?id=60578Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.