UBUNTU-CVE-2019-10072
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-10072
UBUNTU-CVE-2019-10072
Summary:
Details: The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
References: https://ubuntu.com/security/CVE-2019-10072, https://lists.apache.org/thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a@%3Cannounce.tomcat.apache.org%3E, http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.20, http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.41, https://ubuntu.com/security/notices/USN-4128-1, https://ubuntu.com/security/notices/USN-4128-2, https://www.cve.org/CVERecord?id=CVE-2019-10072
Affected packages
Package
Name: tomcat8
Purl: pkg:deb/ubuntu/[email protected]~18.04.3?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
