CVE-2010-3862
published 2010-12-30CVE-2010-3862: The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
2.61%
83.7th percentile
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
| redhat | jboss_remoting | — | — |
| redhat | jboss_remoting | — | — |
| redhat | jboss_remoting | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8wr-qfh4-ggjg: The org
ghsa_unreviewed·2022-05-17·CVSS 2.6
CVE-2010-4265 [LOW] GHSA-q8wr-qfh4-ggjg: The org
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch. NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier.
GHSA
GHSA-3f3h-gc4r-7vvp: The org
ghsa_unreviewed·2022-05-17
CVE-2010-3862 [LOW] CWE-20 GHSA-3f3h-gc4r-7vvp: The org
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Red Hat
jboss-remoting: missing fix for CVE-2010-3862
vendor_redhat·2010-12-08·CVSS 2.6
CVE-2010-4265 [LOW] jboss-remoting: missing fix for CVE-2010-3862
jboss-remoting: missing fix for CVE-2010-3862
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch. NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier.
Red Hat
JBoss Remoting Denial-Of-Service
vendor_redhat·2010-12-01·CVSS 2.6
CVE-2010-3862 [LOW] JBoss Remoting Denial-Of-Service
JBoss Remoting Denial-Of-Service
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4265 jboss-remoting: missing fix for CVE-2010-3862
bugzilla·2010-12-07·CVSS 2.6
CVE-2010-4265 [LOW] CVE-2010-4265 jboss-remoting: missing fix for CVE-2010-3862
CVE-2010-4265 jboss-remoting: missing fix for CVE-2010-3862
The JBoss EAP 430_CP09 security updates for Red Hat Enterprise Linux 4, Red Hat Enterprise Linux 5 and the Customer Support Portal did not, unlike the erratum text stated, provide a fix for CVE-2010-3862, a Denial-of-Service (DoS) flaw in the jboss-remoting component. A missing patch is considered a security regression, and requires a new CVE name. This regression is assigned CVE-2010-4265. It fixes the same issue as CVE-2010-3862 and is specific to JBoss EAP 430_CP09.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 4
JBEAP 4.3.0 for RHEL 5
Via RHSA-2010:0964 https://rhn.redhat.com/errata/RHSA-2010-0964.html
---
This issue has been addressed in following products:
JBoss Enterprise Appl
Bugzilla
CVE-2010-3862 JBoss Remoting Denial-Of-Service
bugzilla·2010-10-08·CVSS 2.6
CVE-2010-3862 [LOW] CVE-2010-3862 JBoss Remoting Denial-Of-Service
CVE-2010-3862 JBoss Remoting Denial-Of-Service
From the original bug report:
Exploiting and thus confirming this vulnerability is extremely simple: Simply
connect to the bisocket control connection (ie. "telnet
") without sending any data on the connection. As long
as this connection is open, no clients can connect to the bisocket control port
because the connections are not accepted at server side.
The cause of this vulnerability is found in method
org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run(),
which contains the accept-loop for the bisocket control connection. After
having accepted a connection, the accept loop thread reads from the newly
created connection expecting the client to send an action code and a listener
id. If the client send
http://securitytracker.com/id?1024813http://www.redhat.com/support/errata/RHSA-2010-0937.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0938.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0939.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0959.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0960.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0961.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0962.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0963.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=641389https://issues.jboss.org/browse/JBPAPP-5253https://issues.jboss.org/browse/JBREM-1261http://securitytracker.com/id?1024813http://www.redhat.com/support/errata/RHSA-2010-0937.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0938.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0939.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0959.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0960.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0961.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0962.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0963.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=641389https://issues.jboss.org/browse/JBPAPP-5253https://issues.jboss.org/browse/JBREM-1261
2010-12-30
Published