CVE-2018-1336
published 2018-08-02CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
20.60%
97.2th percentile
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 7.0.28 – 7.0.86 | — |
| apache | tomcat | 8.0.0 – 8.0.51 | — |
| apache | tomcat | 8.5.0 – 8.5.30 | — |
| apache | tomcat | 9.0.1 – 9.0.7 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| craftcms | cms | 0 – 3.0.34 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_web_server | — | — |
| redhat | jboss_enterprise_web_server | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_apache7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Craft CMS Vulnerable to Server-Side Template Injection
ghsa·2022-05-13
CVE-2018-20465 [HIGH] CWE-1336 Craft CMS Vulnerable to Server-Side Template Injection
Craft CMS Vulnerable to Server-Side Template Injection
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a `{%` string for `craft.app.config.DB.user` and `craft.app.config.DB.password` in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
OSV
tomcat7 vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5388 [HIGH] tomcat7 vulnerabilities
tomcat7 vulnerabilities
It was discovered that Apache Tomcat 7 did not protect applications from the
presence of untrusted client data in an environment variable. A remote
attacker could possible use this vulnerability to redirect the traffic to an
arbitrary proxy and obtain sensitive information. (CVE-2016-5388)
It was discovered that Apache Tomcat 7 mishandled specially crafted input.
An attacker could use this vulnerability to cause a denial of service.
(CVE-2018-1336)
OSV
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
osv·2018-10-17
CVE-2018-1336 [HIGH] In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
GHSA
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
ghsa·2018-10-17
CVE-2018-1336 [HIGH] CWE-835 In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
OSV
tomcat7, tomcat8 vulnerabilities
osv·2018-07-25·CVSS 7.5
CVE-2018-1336 [HIGH] tomcat7, tomcat8 vulnerabilities
tomcat7, tomcat8 vulnerabilities
It was discovered that Tomcat incorrectly handled decoding certain
UTF-8 strings. A remote attacker could possibly use this issue to cause
Tomcat to crash, resulting in a denial of service. (CVE-2018-1336)
It was discovered that the Tomcat WebSocket client incorrectly performed
hostname verification. A remote attacker could possibly use this issue to
intercept sensitive information. (CVE-2018-8034)
OSV
CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Ser
osv·2018-07-24·CVSS 7.5
CVE-2018-1336 [HIGH] CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Ser
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Ubuntu
Apache Tomcat 7 vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 8.1
CVE-2016-5388 [HIGH] Apache Tomcat 7 vulnerabilities
Title: Apache Tomcat 7 vulnerabilities
Summary: Several security issues were fixed in Apache Tomcat 7.
It was discovered that Apache Tomcat 7 did not protect applications from the
presence of untrusted client data in an environment variable. A remote
attacker could possible use this vulnerability to redirect the traffic to an
arbitrary proxy and obtain sensitive information. (CVE-2016-5388)
It was discovered that Apache Tomcat 7 mishandled specially crafted input.
An attacker could use this vulnerability to cause a denial of service.
(CVE-2018-1336)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2018-07-25·CVSS 7.5
CVE-2018-1336 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled decoding certain
UTF-8 strings. A remote attacker could possibly use this issue to cause
Tomcat to crash, resulting in a denial of service. (CVE-2018-1336)
It was discovered that the Tomcat WebSocket client incorrectly performed
hostname verification. A remote attacker could possibly use this issue to
intercept sensitive information. (CVE-2018-8034)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: A bug in the UTF-8 decoder can lead to DoS
vendor_redhat·2018-07-22·CVSS 7.5
CVE-2018-1336 [HIGH] tomcat: A bug in the UTF-8 decoder can lead to DoS
tomcat: A bug in the UTF-8 decoder can lead to DoS
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Statement: Fuse 6.3 and 7 standalone distributions ship but do not use tomcat, and as such are not affected by this flaw; however, Fuse Integration Services 2.0 and Fuse 7 on OpenShift provide the affected artifacts via their respective maven repositories, and will provide fixes for this issue in a future release.
Package: tomcat (Red Hat AMQ Broker 7) - Affected
Package: tomcat (Red Hat BPM Suite 6) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affec
Debian
CVE-2018-1336: tomcat9 - An improper handing of overflow in the UTF-8 decoder with supplementary characte...
vendor_debian·2018·CVSS 7.5
CVE-2018-1336 [HIGH] CVE-2018-1336: tomcat9 - An improper handing of overflow in the UTF-8 decoder with supplementary characte...
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Apache
Apache tomcat: CVE-2018-1336
vendor_apache·CVSS 7.5
CVE-2018-1336 [HIGH] Apache tomcat: CVE-2018-1336
Apache tomcat: CVE-2018-1336
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. This was fixed in revision 1830375 . This issue was reported publicly on 6 April 2018 and formally announced as a vulnerability on 22 July 2018. Affects: 8.0.0.RC1 to 8.0.51 4 May 2018 Fixed in Apache Tomcat 8.5.31 Important: A bug in the UTF-8 decoder can lead to DoS
Severity: high
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18023 ImageMagick: heap-based buffer over-read in the SVGStripString function of coders/svg.c
bugzilla·2018-10-08·CVSS 6.5
CVE-2018-18023 [MEDIUM] CVE-2018-18023 ImageMagick: heap-based buffer over-read in the SVGStripString function of coders/svg.c
CVE-2018-18023 ImageMagick: heap-based buffer over-read in the SVGStripString function of coders/svg.c
A flaw was found in ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the SVGStripString function of coders/svg.c, which allows attackers to cause a denial of service via a crafted SVG image file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1336
Upstream Patches:
https://github.com/ImageMagick/ImageMagick6/commit/a5db4873626f702d2ddd8bc293573493e0a412c0
https://github.com/ImageMagick/ImageMagick/commit/5d71e23b853461dd3628cd1218834fcf13938365
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1637187]
---
Statement:
This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linu
Bugzilla
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [epel-all]
bugzilla·2018-09-03·CVSS 7.5
CVE-2018-1336 [HIGH] CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [epel-all]
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [fedora-all]
bugzilla·2018-09-03·CVSS 7.5
CVE-2018-1336 [HIGH] CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [fedora-all]
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-1336 [HIGH] CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
Flaw affecting tomcat 8.0.0.RC1 to 8.0.51 and 9.0.0.M1 to 9.0.7. An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.
Upstream patch:
http://svn.apache.org/viewvc?view=rev&rev=1830375
http://svn.apache.org/viewvc?view=rev&rev=1830373
References:
https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-9.html
Discussion:
Statement:
Fuse 6.3 and 7 standalone distributions ship but do not use tomcat, and as such are not affected by this flaw; however, Fuse Integration Services 2.0 and Fuse 7 on OpenShift provide the affected artifacts via their respective maven repositories, and will provide fixes fo
http://mail-archives.us.apache.org/mod_mbox/www-announce/201807.mbox/%3C20180722090435.GA60759%40minotaur.apache.org%3Ehttp://www.securityfocus.com/bid/104898http://www.securitytracker.com/id/1041375https://access.redhat.com/errata/RHEA-2018:2188https://access.redhat.com/errata/RHEA-2018:2189https://access.redhat.com/errata/RHSA-2018:2700https://access.redhat.com/errata/RHSA-2018:2701https://access.redhat.com/errata/RHSA-2018:2740https://access.redhat.com/errata/RHSA-2018:2741https://access.redhat.com/errata/RHSA-2018:2742https://access.redhat.com/errata/RHSA-2018:2743https://access.redhat.com/errata/RHSA-2018:2921https://access.redhat.com/errata/RHSA-2018:2930https://access.redhat.com/errata/RHSA-2018:2939https://access.redhat.com/errata/RHSA-2018:2945https://access.redhat.com/errata/RHSA-2018:3768https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/09/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20180817-0001/https://support.f5.com/csp/article/K73008537?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3723-1/https://www.debian.org/security/2018/dsa-4281https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://mail-archives.us.apache.org/mod_mbox/www-announce/201807.mbox/%3C20180722090435.GA60759%40minotaur.apache.org%3Ehttp://www.securityfocus.com/bid/104898http://www.securitytracker.com/id/1041375https://access.redhat.com/errata/RHEA-2018:2188https://access.redhat.com/errata/RHEA-2018:2189https://access.redhat.com/errata/RHSA-2018:2700https://access.redhat.com/errata/RHSA-2018:2701https://access.redhat.com/errata/RHSA-2018:2740https://access.redhat.com/errata/RHSA-2018:2741https://access.redhat.com/errata/RHSA-2018:2742https://access.redhat.com/errata/RHSA-2018:2743https://access.redhat.com/errata/RHSA-2018:2921https://access.redhat.com/errata/RHSA-2018:2930https://access.redhat.com/errata/RHSA-2018:2939https://access.redhat.com/errata/RHSA-2018:2945https://access.redhat.com/errata/RHSA-2018:3768https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/09/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20180817-0001/https://support.f5.com/csp/article/K73008537?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3723-1/https://www.debian.org/security/2018/dsa-4281https://www.oracle.com/security-alerts/cpuapr2020.html
2018-08-02
Published