Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1607591 - (CVE-2018-1336) CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20180722,repo...
: Security
Depends On: 1608655 1614559 1624929 1624931 1608607 1608608 1608656 1614560
Blocks: 1607593
  Show dependency treegraph
 
Reported: 2018-07-23 15:29 EDT by Pedro Sampaio
Modified: 2018-10-27 10:10 EDT (History)
86 users (show)

See Also:
Fixed In Version: tomcat 8.0.52, tomcat 8.5.31, tomcat 9.0.8, tomcat 7.0.88
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2700 None None None 2018-09-12 13:04 EDT
Red Hat Product Errata RHSA-2018:2701 None None None 2018-09-12 13:14 EDT
Red Hat Product Errata RHSA-2018:2740 None None None 2018-09-24 17:47 EDT
Red Hat Product Errata RHSA-2018:2741 None None None 2018-09-24 18:05 EDT
Red Hat Product Errata RHSA-2018:2742 None None None 2018-09-24 18:09 EDT
Red Hat Product Errata RHSA-2018:2743 None None None 2018-09-24 18:10 EDT
Red Hat Product Errata RHSA-2018:2921 None None None 2018-10-16 04:34 EDT
Red Hat Product Errata RHSA-2018:2930 None None None 2018-10-16 13:06 EDT
Red Hat Product Errata RHSA-2018:2939 None None None 2018-10-17 15:30 EDT
Red Hat Product Errata RHSA-2018:2945 None None None 2018-10-18 03:15 EDT

  None (edit)
Description Pedro Sampaio 2018-07-23 15:29:47 EDT
Flaw affecting tomcat 8.0.0.RC1 to 8.0.51 and 9.0.0.M1 to 9.0.7. An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.

Upstream patch:

http://svn.apache.org/viewvc?view=rev&rev=1830375
http://svn.apache.org/viewvc?view=rev&rev=1830373

References:

https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-9.html
Comment 9 Chess Hazlett 2018-08-17 15:28:45 EDT
Statement:

Fuse 6.3 and 7 standalone distributions ship but do not use tomcat, and as such are not affected by this flaw; however, Fuse Integration Services 2.0 and Fuse 7 on OpenShift provide the affected artifacts via their respective maven repositories, and will provide fixes for this issue in a future release.
Comment 10 Laura Pardo 2018-09-03 11:48:49 EDT
Created tomcat tracking bugs for this issue:

Affects: epel-all [bug 1624931]
Affects: fedora-all [bug 1624929]
Comment 11 errata-xmlrpc 2018-09-12 13:03:38 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2018:2700 https://access.redhat.com/errata/RHSA-2018:2700
Comment 12 errata-xmlrpc 2018-09-12 13:13:42 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 3 for RHEL 7
  Red Hat JBoss Web Server 3 for RHEL 6

Via RHSA-2018:2701 https://access.redhat.com/errata/RHSA-2018:2701
Comment 14 errata-xmlrpc 2018-09-24 17:47:12 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:2740 https://access.redhat.com/errata/RHSA-2018:2740
Comment 15 errata-xmlrpc 2018-09-24 18:05:06 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2018:2741 https://access.redhat.com/errata/RHSA-2018:2741
Comment 16 errata-xmlrpc 2018-09-24 18:08:51 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5

Via RHSA-2018:2742 https://access.redhat.com/errata/RHSA-2018:2742
Comment 17 errata-xmlrpc 2018-09-24 18:10:15 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:2743 https://access.redhat.com/errata/RHSA-2018:2743
Comment 19 errata-xmlrpc 2018-10-16 04:34:23 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:2921 https://access.redhat.com/errata/RHSA-2018:2921
Comment 21 errata-xmlrpc 2018-10-16 13:06:33 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Operations Network

Via RHSA-2018:2930 https://access.redhat.com/errata/RHSA-2018:2930
Comment 22 errata-xmlrpc 2018-10-17 15:30:10 EDT
This issue has been addressed in the following products:

  Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8

Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939
Comment 23 errata-xmlrpc 2018-10-18 03:15:18 EDT
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes (text-only advisories)

Via RHSA-2018:2945 https://access.redhat.com/errata/RHSA-2018:2945
Comment 28 Jean-frederic Clere 2018-10-24 06:30:52 EDT
Oops https://bugzilla.redhat.com/show_bug.cgi?id=1608656 it was fixed in 6.4.21

Note You need to log in before you can comment on or make changes to this bug.