CVE-2018-1336: High severity Apache Tomcat vulnerability
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Other sources
Flaw affecting tomcat 8.0.0.RC1 to 8.0.51 and 9.0.0.M1 to 9.0.7. An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.
Upstream patch:
http://svn.apache.org/viewvc?view=rev&rev=1830375 http://svn.apache.org/viewvc?view=rev&rev=1830373
References:
https://tomcat.apache.org/security-8.html https://tomcat.apache.org/security-9.html
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.0.51 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.8 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 7.0.87 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.31 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.43-2~deb11u10Fixed in 9.0.107-0+deb11u2Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.115-1 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.52 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.31 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.8 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.88 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.31 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.8 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.0.52 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 7.0.87
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1336?
CVE-2018-1336 has a high severity rating due to its potential to cause a Denial of Service through an infinite loop in the UTF-8 decoder.
How do I fix CVE-2018-1336?
To address CVE-2018-1336, upgrade to Apache Tomcat version 8.0.52 and later, 8.5.31 and later, 9.0.8 and later, or 7.0.87 and later depending on your current version.
Which versions of Apache Tomcat are affected by CVE-2018-1336?
CVE-2018-1336 affects Apache Tomcat versions 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Can CVE-2018-1336 be exploited remotely?
Yes, CVE-2018-1336 can be exploited remotely to trigger a Denial of Service condition.
What applications are impacted by CVE-2018-1336?
CVE-2018-1336 impacts applications running on affected versions of Apache Tomcat when processing UTF-8 encoded data.