#VU1185 Denial of service in Apache Tomcat - CVE-2016-6817
Published: November 22, 2016
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a DoS attack.
The vulnerability exists due to boundary error when parsing HTTP/2 headers. A remote attacker can send a specially crafted HTTP/2 header longer than available buffer and trigger infinite loop.
Successful exploitation of the vulnerability may result in denial of service.