First published: Thu Dec 15 2011(Updated: )
JBoss Web will enter into an infinite loop when a surrogate pair character is placed at the boundary of an internal buffer. A remote attacker could exploit this flaw to trigger a denial-of-service attack against a JBoss Web server that is hosting applications with UTF-8 character encoding enabled, or that will include user-supplied UTF-8 strings in a response.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Application Platform | <=5.1.2 | |
Redhat Jboss Enterprise Brms Platform | <=5.1.0 | |
Redhat Jboss Communications Platform | <=5.1 | |
Redhat Jboss Enterprise Web Platform | <=5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.