CVE-2021-41079
published 2021-09-16CVE-2021-41079: Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.18%
93.6th percentile
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 10.0.0 – 10.0.2 | — |
| apache | tomcat | >= 8.5.0 < 8.5.64 | 8.5.64 |
| apache | tomcat | >= 9.0.0 < 9.0.44 | 9.0.44 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.53-1 (bookworm) | tomcat9 9.0.53-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2022-03-31·CVSS 4.3
CVE-2021-33037 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
vendor_redhat·2021-09-15·CVSS 7.5
CVE-2021-41079 [HIGH] CWE-400 tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
A flaw was found in Apache Tomcat. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet can trigger an infinite loop, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Statement: In Red Hat Certificate System versions 9 and older, the version of Tomcat used is not affected by this flaw.
In Red Hat Certificate
Debian
CVE-2021-41079: tomcat9 - Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did no...
vendor_debian·2021·CVSS 7.5
CVE-2021-41079 [HIGH] CVE-2021-41079: tomcat9 - Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did no...
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 9.0.53-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u2)
forky: resolved (fixed in 9.0.53-1)
sid: resolved (fixed in 9.0.53-1)
trixie: resolved (fixed in 9.0.53-1)
Apache
Apache tomcat: CVE-2021-41079
vendor_apache·CVSS 7.5
CVE-2021-41079 [HIGH] Apache tomcat: CVE-2021-41079
Apache tomcat: CVE-2021-41079
When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service. This was fixed with commit b90d4fc1 . This issue was first reported to the Apache Tomcat Security Team by Thomas Wozenilek on 26 February 2021 but could not be confirmed. A speculative fix was applied on 3 March 2021. On 14 September 2021 David Frankson of Infinite Campus independently reported the issue and included a test case. This allowed both the issue and the speculative fix to be verified. The issue was made public on 15 September 2021. Affects: 8.5.0 to 8.5.63 Important: Information Disclosure
OSV
tomcat8, tomcat9 vulnerabilities
osv·2024-08-01·CVSS 7.0
CVE-2020-9484 [HIGH] tomcat8, tomcat9 vulnerabilities
tomcat8, tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code. This issue only affected
tomcat8 for Ubuntu 18.04 LTS (CVE-2020-9484)
It was discovered that Tomcat incorrectly handled certain HTTP/2 connection
requests. A remote attacker could use this issue to obtain wrong responses
possibly containing sensitive information. This issue only affected tomcat8
for Ubuntu 18.04 LTS (CVE-2021-25122)
Thomas Wozenilek discovered that Tomcat incorrectly handled certain TLS
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected tomcat8 for Ubuntu 18.04 LTS
(CVE-2021-41079)
Trung
OSV
tomcat9 vulnerabilities
osv·2022-03-31·CVSS 4.3
CVE-2020-13943 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat incorrectly performed input verification.
A remote attacker could possibly use this issue to intercept sensitive
information. (CVE-2020-13943, CVE-2020-17527, CVE-2021-25122, CVE-2021-30640)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-33037)
It was discovered that Tomcat did not properly validate the input length. An
attacker could possibly use this to trigger an infinite loop, resulting in a
denial of service. (CVE-2021-25329, CVE-2021-41079)
OSV
Infinite loop in Tomcat due to parsing error
osv·2021-09-20
CVE-2021-41079 [HIGH] Infinite loop in Tomcat due to parsing error
Infinite loop in Tomcat due to parsing error
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
GHSA
Infinite loop in Tomcat due to parsing error
ghsa·2021-09-20
CVE-2021-41079 [HIGH] CWE-20 Infinite loop in Tomcat due to parsing error
Infinite loop in Tomcat due to parsing error
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
OSV
CVE-2021-41079: Apache Tomcat 8
osv·2021-09-16·CVSS 7.5
CVE-2021-41079 [HIGH] CVE-2021-41079: Apache Tomcat 8
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
No detection rules found.
No public exploits indexed.
arXiv
Forecasting the risk of software choices: A model to foretell security vulnerabilities from library dependencies and source code evolution
arxiv_fulltext·2024-11-17
Forecasting the risk of software choices: A model to foretell security vulnerabilities from library dependencies and source code evolution
Carlos E.\ Budde
0000-0001-8807-1548
[email protected]
Ranindya Paramitha
0000-0002-6682-4243
[email protected]
University of Trento
Trento
Italy
Fabio Massacci
0000-0002-1091-8486
University of Trento
Trento
Italy
Vre Universiteit
Amsterdam
The Netherlands
Budde, Paramitha, Massacci
## Abstract
Software security mainly studies vulnerability detection: is my code vulnerable today?
This hinders risk estimation, so new approaches are emerging to forecast the occurrence of future vulnerabilities.
While useful, these approaches are coarse-grained and hard to employ for project-specific technical decisions.
We introduce a model capable of vulnerability forecasting at library level.
Formalising source-code evolution in time together with library dependency, our model
Bugzilla
CVE-2021-41079 tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
bugzilla·2021-09-16·CVSS 7.5
CVE-2021-41079 [HIGH] CVE-2021-41079 tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
CVE-2021-41079 tomcat: Infinite loop while reading an unexpected TLS packet when using OpenSSL JSSE engine
Apache Tomcat did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service. This issue affects the version of Apache Tomcat 10.0.0-M1 to 10.0.2; 9.0.0-M1 to 9.0.43; 8.5.0 to 8.5.63.
Upstream commits:
Tomcat 10.0.4: https://github.com/apache/tomcat/commit/34115fb3c83f6cd97772232316a492a4cc5729e0
Tomcat 9.0.44: https://github.com/apache/tomcat/commit/d4b340fa8feaf55831f9a59350578f7b6ca048b8
Tomcat 8.5.64: https://github.com/apache/tomcat/commit/b90d4fc1ff44f30e4b3aba622ba6677e3f003822
Reference:
https://lists.apache.org/thread
https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/09/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20211008-0005/https://www.debian.org/security/2021/dsa-4986https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/09/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20211008-0005/https://www.debian.org/security/2021/dsa-4986
2021-09-16
Published