PT-2010-5385 · Red Hat · Jboss-Remoting+1
CVE-2010-4265
·
Publicado
2010-12-30
·
Atualizado
2023-02-13
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) versions 4.3 through 4.3.0.CP09
JBoss Remoting versions 2.2.x through 2.2.3.SP3
JBoss Remoting versions 2.5.x through 2.5.3.SP1
Description
The issue allows remote attackers to cause a denial of service by establishing a bisocket control connection TCP session and then not sending any application data. This is related to a missing patch.
Recommendations
For Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) versions 4.3 through 4.3.0.CP09, update to a version that includes the missing patch.
For JBoss Remoting versions 2.2.x through 2.2.3.SP3, update to version 2.2.3.SP4 or later.
For JBoss Remoting versions 2.5.x through 2.5.3.SP1, update to version 2.5.3.SP2 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jboss-Remoting
Red Hat Jboss Enterprise Application Platform