Back

MEDIUM

JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary

Published Feb 10, 2014

Description

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 10, 2014
Updated Aug 7, 2024
Reserved Nov 29, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jan 31, 2012