CVE-2010-3862: Input Validation
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3862?
The severity of CVE-2010-3862 is rated as moderate.
How do I fix CVE-2010-3862?
To fix CVE-2010-3862, upgrade JBoss Remoting to version 2.2.3.SP4 or later, and JBoss EAP to version 4.3.0.CP10 or later.
Which versions are affected by CVE-2010-3862?
CVE-2010-3862 affects JBoss Remoting versions prior to 2.2.3.SP4 and JBoss EAP versions from 4.3.0 to 4.3.0.CP09.
What component does CVE-2010-3862 affect?
CVE-2010-3862 specifically affects the BisocketServerInvoker in JBoss Remoting.
Is there a workaround for CVE-2010-3862?
No specific workaround is recommended for CVE-2010-3862; upgrading to a fixed version is the best option.