Back

HIGH

tomcat: A bug in the UTF-8 decoder can lead to DoS

Published Aug 2, 2018

Description

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Affected products

Remediation

Red Hat statement

Fuse 6.3 and 7 standalone distributions ship but do not use tomcat, and as such are not affected by this flaw; however, Fuse Integration Services 2.0 and Fuse 7 on OpenShift provide the affected artifacts via their respective maven repositories, and will provide fixes for this issue in a future release.

Metrics

Weaknesses (1)

References (66)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 2, 2018
Updated Nov 14, 2024
Reserved Dec 7, 2017
CISA Vulnrichment
Updated Dec 12, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 22, 2018
GHSA-M59C-JPC8-M2X4