CERT-In Vulnerability Note
CIVN-2021-0265
Denial of Services Vulnerability in Red Hat JBoss Web Server
Original Issue Date:October 18, 2021
Severity Rating: HIGH
Software Affected
- Red Hat JBoss Web Server 5.5.1
Overview
A Vulnerability has been reported in Red Hat JBoss Web server which could be exploited by a remote attacker to cause denial of service (DoS) attack on the targeted system.
Description
The vulnerability exists in Red Hat JBoss Web server due to infinite loop when processing certain TLS packets. A remote attacker could exploit this vulnerability by sending a specially crafted packet to the application.
Successful exploitation of this vulnerability could allow a remote attacker to cause denial of service (DoS) attack on the targeted system.
Solution
Apply appropriate fix/patches as mentioned in the following link
https://access.redhat.com/errata/RHSA-2021:3741
https://access.redhat.com/errata/RHSA-2021:3743
Vendor Information
Redhat
https://access.redhat.com/errata/RHSA-2021:3743
https://access.redhat.com/errata/RHSA-2021:3741
References
Redhat
https://access.redhat.com/errata/RHSA-2021:3741
https://access.redhat.com/errata/RHSA-2021:3743
CVE Name
CVE-2021-41079
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|