CVE-2011-4610

CWE-119Buffer Overflow5 documents5 sources
Severity
5.0MEDIUM
EPSS
1.5%
top 18.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateMay 17

Description

JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-hh9c-c3q8-gv72: JBoss Web, as used in Red Hat JBoss Communications Platform before 52022-05-17
CVEList
CVE-2011-4610: JBoss Web, as used in Red Hat JBoss Communications Platform before 52014-02-10

📋Vendor Advisories

1
Red Hat
JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary2012-01-31

💬Community

1
Bugzilla
CVE-2011-4610 JBoss Web remote denial of service when surrogate pair character is placed at buffer boundary2011-12-15
CVE-2011-4610 (MEDIUM CVSS 5) | JBoss Web | cvebase.io