Infinite loop in Apache Tomcat - CVE-2020-13935

 

Infinite loop in Apache Tomcat - CVE-2020-13935

Published: July 14, 2020 / Updated: June 2, 2022


Vulnerability identifier: #VU29723
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13935
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing payload length in a WebSocket frame. A remote attacker can send a specially crafted request to the application, consume all available system resources and cause denial of service conditions.


Affected software

Apache Tomcat
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Opensuse
Ubuntu
Dell Support Assist Enterprise
Oracle Agile Engineering Data Management
Traffix SDC
tomcat (Red Hat package)
libtomcat8-java (Ubuntu package)
tomcat8 (Ubuntu package)
libtomcat9-embed-java (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat9 (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Debian package)
MySQL Enterprise Monitor
Oracle Database Server
Oracle Commerce Guided Search
Oracle Managed File Transfer
Instantis EnterpriseTrack
SAN Volume Controller and Storwize Family

How to mitigate CVE-2020-13935

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.105, 8.5.57, 9.0.37, 10.0.0-M7
Dell Support Assist Enterprise - update to 4.00.06.00
tomcat (Red Hat package) - update to 7.0.76-15.el7
MySQL Enterprise Monitor - update to 8.0.22
SAN Volume Controller and Storwize Family - addressed in versions 7.8.1.13, 8.2.1.12, 8.3.1.3
libtomcat8-java (Ubuntu package) - update to 8.0.32-1ubuntu1.13
tomcat8 (Ubuntu package) - update to 8.0.32-1ubuntu1.13
libtomcat9-embed-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
libtomcat9-java (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9-common (Ubuntu package) - update to 9.0.31-1ubuntu0.1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins