CVE-2018-1041

Summary

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Affected Software

VendorProductVersion RangeStatus
Red Hat, Inc.jboss-remotingsince 3.3.10affected

Weaknesses

  • CWE-835: CWE-835

ADP Enrichment

CVE Program Container

Additional References

References