CVE-2017-6056
published 2017-02-17CVE-2017-6056: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
7.49%
93.9th percentile
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.1HIGH
vendor_apache7.5HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf6r-cgfg-q96j: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of ser
ghsa_unreviewed·2022-05-13·CVSS 7.1
CVE-2017-6056 [HIGH] CWE-835 GHSA-vf6r-cgfg-q96j: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of ser
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
OSV
CVE-2017-6056: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of ser
osv·2017-02-13·CVSS 7.1
CVE-2017-6056 [HIGH] CVE-2017-6056: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of ser
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Ubuntu
Tomcat vulnerability
vendor_ubuntu·2017-02-20
CVE-2017-6056 Tomcat vulnerability
Title: Tomcat vulnerability
Summary: Tomcat could be made to consume resources if it received specially crafted
network traffic.
It was discovered that Tomcat incorrectly handled certain HTTP requests. A
remote attacker could possibly use this issue to cause Tomcat to consume
resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: Infinite loop in the processing of https requests
vendor_redhat·2015-02-06·CVSS 7.1
CVE-2017-6056 [HIGH] CWE-835 tomcat: Infinite loop in the processing of https requests
tomcat: Infinite loop in the processing of https requests
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.
Statement: This issue was made easier to exploit, causing a denial of service when the patch for CVE-2016-681
Apache
Apache tomcat: CVE-2017-6056
vendor_apache·CVSS 7.5
CVE-2017-6056 [HIGH] Apache tomcat: CVE-2017-6056
Apache tomcat: CVE-2017-6056
In February 2015 a single user reported high CPU usage ( 57544 ) which was traced to a tight loop. However, it was not clear how the conditions necessary to enter the loop were being created. There was no evidence that indicated that the loop was user triggerable. The only potential paths identified by code inspection depended on application bugs (retaining references to request objects and accessing after the request had completed). It was (and still is) believed that an application bug was the most likely root cause. Therefore, 57544 was not treated as a DoS vulnerability. In November 2016,
Severity: high
No detection rules found.
No public exploits indexed.
Tenable
Oracle Critical Patch Update for October Contains 180 Fixes
blogs_tenable·2019-10-16
Oracle Critical Patch Update for October Contains 180 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2017-6056 tomcat: Infinite loop in the processing of https requests
bugzilla·2017-02-14·CVSS 7.1
CVE-2017-6056 [HIGH] CVE-2017-6056 tomcat: Infinite loop in the processing of https requests
CVE-2017-6056 tomcat: Infinite loop in the processing of https requests
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.
Upstream patch:
https://github.com/apache/tomcat80/commit/614e7f78aecc429d8740bb59900c2f9fbc86a788#diff-2aeb244142da5fcb78a54e23f717fcd2
Upstream bug:
https://bz.apache.org/bugzilla/show_bug.cgi?id=57544
Discussion:
External References:
http://tomcat.apache.org/security-7.html
https://access.redhat.com/articles/2991951
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 6.4.14
Via RHSA-2017:0517 https://rhn.redhat.com/errata/RHSA-2017-0517.html
---
This issue has been addressed
arXiv
Can Highlighting Help GitHub Maintainers Track Security Fixes?
arxiv_fulltext·2024-11-18
Can Highlighting Help GitHub Maintainers Track Security Fixes?
Can Highlighting Help GitHub Maintainers Track Security Fixes?
Xueqing Liu
Stevens Institute of Technology
[email protected]
Yuchen Xiong
Nanjing University
[email protected]
Qiushi Liu
Zhejiang University
[email protected]
Jiangrui Zheng
Stevens Institute of Technology
[email protected]
## Abstract
In recent years, the rapid growth of security vulnerabilities poses great challenges to tracing and managing them. For example, it was reported that the NVD database experienced significant delays due to the shortage of maintainers . The delays in updating the patch link information can pose significant security risks, as organizations may remain vulnerable to known exploits before the patch link is updated. Furthermore, the delay creates challenges for third-party
http://rhn.redhat.com/errata/RHSA-2017-0517.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0826.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0827.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0828.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0829.htmlhttp://www.debian.org/security/2017/dsa-3787http://www.debian.org/security/2017/dsa-3788http://www.securityfocus.com/bid/96293http://www.securitytracker.com/id/1037860https://bugs.debian.org/851304https://bz.apache.org/bugzilla/show_bug.cgi?id=60578https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3Ehttps://lists.debian.org/debian-security-announce/2017/msg00038.htmlhttps://lists.debian.org/debian-security-announce/2017/msg00039.htmlhttps://security.netapp.com/advisory/ntap-20180731-0002/https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0517.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0826.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0827.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0828.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0829.htmlhttp://www.debian.org/security/2017/dsa-3787http://www.debian.org/security/2017/dsa-3788http://www.securityfocus.com/bid/96293http://www.securitytracker.com/id/1037860https://bugs.debian.org/851304https://bz.apache.org/bugzilla/show_bug.cgi?id=60578https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb90e7af9c22db4%40%3Cissues.activemq.apache.org%3Ehttps://lists.debian.org/debian-security-announce/2017/msg00038.htmlhttps://lists.debian.org/debian-security-announce/2017/msg00039.htmlhttps://security.netapp.com/advisory/ntap-20180731-0002/https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2017-02-17
Published