UBUNTU-CVE-2020-13935
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-13935
UBUNTU-CVE-2020-13935
Summary:
Details: The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
References: https://ubuntu.com/security/CVE-2020-13935, https://www.openwall.com/lists/oss-security/2020/07/14/3, https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E, https://ubuntu.com/security/notices/USN-4448-1, https://ubuntu.com/security/notices/USN-4596-1, https://www.cve.org/CVERecord?id=CVE-2020-13935
Affected packages
Package
Name: tomcat7
Purl: pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
