Apache Tomcat HTTP/2 Denial of Service Vulnerability
Bug #1885738 reported by
it0001
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tomcat8 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Triaged
|
Undecided
|
Unassigned | ||
Focal |
Invalid
|
Undecided
|
Unassigned | ||
tomcat9 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Bionic |
Triaged
|
Undecided
|
Unassigned | ||
Focal |
Triaged
|
Undecided
|
Unassigned |
Bug Description
Hi Launchpad Team,
An error related to handling HTTP/2 requests can be exploited to trigger high CPU usage and subsequently trigger a DoS condition.
The vulnerability is reported in versions prior to 8.5.56 and prior to 9.0.36.
References:
1. http://
2. http://
Solution:
Update to version 8.5.56 or 9.0.36.
This issue affects Ubuntu 18, and probably other versions as well.
Please take appropriate measures.
Kind regards,
it0001
Changed in tomcat9 (Ubuntu Focal): | |
status: | New → Triaged |
Changed in tomcat9 (Ubuntu Bionic): | |
status: | New → Triaged |
Changed in tomcat8 (Ubuntu): | |
status: | Triaged → Invalid |
Changed in tomcat8 (Ubuntu Bionic): | |
status: | New → Triaged |
Changed in tomcat8 (Ubuntu Focal): | |
status: | New → Invalid |
To post a comment you must log in.
Problem affecting Ubuntu 18. Probably also other versions of Ubuntu.