CVE-2017-6056
Last modified
CVE-2017-6056 is a vulnerability of currently unknown severity. It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. EPSS estimates a 7.49% chance of exploitation in the next 30 days.
Description
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 8.0 |
References
- http://rhn.redhat.com/errata/RHSA-2017-0517.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3787Third Party Advisory
- http://www.debian.org/security/2017/dsa-3788Third Party Advisory
- http://www.securityfocus.com/bid/96293Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037860Third Party Advisory, VDB Entry
- https://bugs.debian.org/851304Issue Tracking, Third Party Advisory
- https://bz.apache.org/bugzilla/show_bug.cgi?id=60578Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00038.htmlThird Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00039.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180731-0002/Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0517.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0826.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0827.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0828.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0829.htmlThird Party Advisory
- http://www.debian.org/security/2017/dsa-3787Third Party Advisory
- http://www.debian.org/security/2017/dsa-3788Third Party Advisory
- http://www.securityfocus.com/bid/96293Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037860Third Party Advisory, VDB Entry
- https://bugs.debian.org/851304Issue Tracking, Third Party Advisory
- https://bz.apache.org/bugzilla/show_bug.cgi?id=60578Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00038.htmlThird Party Advisory
- https://lists.debian.org/debian-security-announce/2017/msg00039.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180731-0002/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6056?
How severe is CVE-2017-6056?
How do I fix CVE-2017-6056?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6050A SQL Injection issue was discovered in Ecava IntegraXor Ver…
- CVE-2017-6051An Uncontrolled Search Path Element issue was discovered in …
- CVE-2017-6052A Man-in-the-Middle issue was discovered in Hyundai Motor Am…3.7
- CVE-2017-6053A Cross-Site Scripting issue was discovered in Trihedral VTS…
- CVE-2017-6054A Use of Hard-Coded Cryptographic Key issue was discovered i…7.5
- CVE-2017-6055XML external entity (XXE) vulnerability in eParakstitajs 3 b…
- CVE-2017-6058Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c…7.5
- CVE-2017-6059Mod_auth_openidc.c in the Ping Identity OpenID Connect authe…7.5
- CVE-2017-6060Stack-based buffer overflow in jstest_main.c in mujstest in …7.8
- CVE-2017-6061Cross-site scripting (XSS) vulnerability in the help compone…
- CVE-2017-6062The "OpenID Connect Relying Party and OAuth 2.0 Resource Ser…
- CVE-2017-6065SQL injection vulnerability in inc/lib/Control/Backend/menus…
Are you affected by CVE-2017-6056?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
