CVE-2016-6817: Buffer Overflow
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6817?
CVE-2016-6817 has a severity rating that allows for denial of service attacks due to an infinite loop in the HTTP/2 header parser of affected Apache Tomcat versions.
Which versions of Apache Tomcat are affected by CVE-2016-6817?
CVE-2016-6817 affects Apache Tomcat versions 8.5.0 through 8.5.6 and 9.0.0.M1 through 9.0.0.M11.
How do I fix CVE-2016-6817?
To fix CVE-2016-6817, upgrade to Apache Tomcat version 8.5.8 or later, or 9.0.0.M12 or later.
What type of vulnerability is CVE-2016-6817?
CVE-2016-6817 is categorized as a denial of service vulnerability affecting the HTTP/2 header parsing functionality.
Can CVE-2016-6817 cause application downtime?
Yes, CVE-2016-6817 can cause application downtime due to its denial of service nature, leading to unresponsiveness.