Denial of service in Undertow - CVE-2017-2670
Published: July 12, 2017 / Updated: July 17, 2017
Vulnerability identifier: #VU7547
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2670
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when closing TCP sockets in Undertow. A remote attacker can create and close multiple TCP connections, which my result in infinite loop and server crash.
Affected software
Undertow
Debian Linux
JBoss Enterprise Application Platform
Debian Linux
JBoss Enterprise Application Platform
How to mitigate CVE-2017-2670
Update to version 1.4.18.