PT-2013-4900 · Red Hat · Red Hat Jboss Soa Platform+3

James Livingston

·

Publicado

2013-10-01

·

Atualizado

2013-10-31

·

CVE-2013-4210

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Remoting versions 5.3.1 GA and earlier Red Hat JBoss SOA Platform version 5.3.1 GA Red Hat Web Platform version 5.2.0 Red Hat Enterprise Application Platform version 5.2.0
Description The issue allows remote attackers to cause a denial of service, specifically file descriptor consumption, via unspecified vectors. This is related to the org.jboss.remoting.transport.socket.ServerThread class.
Recommendations For Red Hat JBoss Remoting version 5.3.1 GA and earlier, consider restricting access to the ServerThread class until a patch is available. For Red Hat JBoss SOA Platform version 5.3.1 GA, update to a version that includes a fix for the issue. For Red Hat Web Platform version 5.2.0, update to a version that includes a fix for the issue. For Red Hat Enterprise Application Platform version 5.2.0, update to a version that includes a fix for the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-4210
RHSA-2013:1369
RHSA-2013:1370

Produtos afetados

Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Remoting
Red Hat Jboss Soa Platform
Red Hat Web Platform