First published: Thu Sep 01 2016(Updated: )
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/resteasy | <3.1.0. | 3.1.0. |
redhat/resteasy | <3.0.20. | 3.0.20. |
Red Hat Resteasy Base JAX-RS API |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6346 is classified as a denial of service vulnerability.
To fix CVE-2016-6346, upgrade your RESTEasy package to version 3.1.0 or later, or to version 3.0.20 or later.
CVE-2016-6346 affects RESTEasy versions prior to 3.1.0 and versions prior to 3.0.20.
Yes, CVE-2016-6346 can be exploited by remote attackers to launch a denial of service attack.
The vulnerability in CVE-2016-6346 is related to the GZIPInterceptor component in RESTEasy.