First published: Thu Dec 15 2011(Updated: )
JBoss Web will enter into an infinite loop when a surrogate pair character is placed at the boundary of an internal buffer. A remote attacker could exploit this flaw to trigger a denial-of-service attack against a JBoss Web server that is hosting applications with UTF-8 character encoding enabled, or that will include user-supplied UTF-8 strings in a response.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Web |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-767871 is high as it allows a denial-of-service attack on JBoss Web servers.
To fix REDHAT-BUG-767871, apply the appropriate patches and updates provided by Red Hat.
REDHAT-BUG-767871 affects Red Hat JBoss Web applications that have UTF-8 character encoding enabled.
Yes, REDHAT-BUG-767871 can be exploited remotely by an attacker to induce a denial-of-service condition.
Exploiting REDHAT-BUG-767871 can cause an infinite loop affecting JBoss Web, leading to service interruptions.