Denial of service in Apache Tomcat - CVE-2016-6817
Published: November 22, 2016
Vulnerability details
The vulnerability allows a remote attacker to perform a DoS attack.
The vulnerability exists due to boundary error when parsing HTTP/2 headers. A remote attacker can send a specially crafted HTTP/2 header longer than available buffer and trigger infinite loop.
Successful exploitation of the vulnerability may result in denial of service.
Affected software
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 840 9840-AE1 & 9843-AE1
EMC Cloud Tiering Appliance
Fedora
IBM FlashSystem V9000
IBM Storwize V7000
IBM Storwize V5000
IBM SAN Volume Controller
IBM Storwize V3700
IBM Storwize V3500
tomcat
How to mitigate CVE-2016-6817
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM SAN Volume Controller - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
tomcat - addressed in versions 8.0.39-1.fc23, 8.0.39-1.fc24, 8.0.39-1.fc25
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Fedora 24 update for tomcat
- Fedora 23 update for tomcat
- Fedora 25 update for tomcat