First published: Fri Oct 08 2010(Updated: )
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Remoting | =2.2.0 | |
Redhat Jboss Remoting | =2.2.2-sp10 | |
Redhat Jboss Remoting | =2.2.2-sp11 | |
Redhat Jboss Remoting | =2.2.2-sp2 | |
Redhat Jboss Remoting | =2.2.2-sp4 | |
Redhat Jboss Remoting | =2.2.2-sp7 | |
Redhat Jboss Remoting | =2.2.2-sp8 | |
Redhat Jboss Remoting | =2.2.3 | |
Redhat Jboss Remoting | =2.2.3-sp1 | |
Redhat Jboss Remoting | =2.2.3-sp2 | |
Redhat Jboss Remoting | =2.2.3-sp3 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp01 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp02 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp03 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp04 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp05 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp06 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp07 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp08 | |
Red Hat JBoss Enterprise Application Platform | =4.3.0-cp09 | |
Red Hat JBoss Enterprise Application Platform | =5.1.0 | |
Redhat Jboss Enterprise Web Platform | =5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.