CVE-2023-1973
published 2024-11-07CVE-2023-1973: A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.29%
67.0th percentile
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.18-1 (forky) | undertow 2.3.18-1 (forky) |
| redhat | undertow | >= 0 < 2.3.18-1 | 2.3.18-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: unrestricted request storage leads to memory exhaustion
vendor_redhat·2024-04-04·CVSS 7.5
CVE-2023-1973 [HIGH] CWE-20 undertow: unrestricted request storage leads to memory exhaustion
undertow: unrestricted request storage leads to memory exhaustion
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
Red Hat
ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
vendor_redhat·2023-07-17·CVSS 5.5
CVE-2023-38559 [MEDIUM] CWE-125 ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
ghostscript: Out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in DoS
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
Package: ghostscript (Red Hat Enterprise Linux 6) - Out of support scope
Package: ghostscript (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/ghostscript (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2023-1973: undertow - A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a m...
vendor_debian·2023·CVSS 7.5
CVE-2023-1973 [HIGH] CVE-2023-1973: undertow - A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a m...
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
Scope: local
forky: resolved (fixed in 2.3.18-1)
sid: resolved (fixed in 2.3.18-1)
OSV
CVE-2023-1973: A flaw was found in Undertow package
osv·2024-11-07·CVSS 7.5
CVE-2023-1973 [HIGH] CVE-2023-1973: A flaw was found in Undertow package
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
OSV
Undertow Denial of Service vulnerability
osv·2024-11-07
CVE-2023-1973 [MEDIUM] Undertow Denial of Service vulnerability
Undertow Denial of Service vulnerability
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
GHSA
Undertow Denial of Service vulnerability
ghsa·2024-11-07
CVE-2023-1973 [MEDIUM] CWE-20 Undertow Denial of Service vulnerability
Undertow Denial of Service vulnerability
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1674https://access.redhat.com/errata/RHSA-2024:1675https://access.redhat.com/errata/RHSA-2024:1676https://access.redhat.com/errata/RHSA-2024:1677https://access.redhat.com/errata/RHSA-2024:2763https://access.redhat.com/errata/RHSA-2024:2764https://access.redhat.com/security/cve/CVE-2023-1973https://bugzilla.redhat.com/show_bug.cgi?id=2185662
2024-11-07
Published