What the vulnerability does

01Description

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Key dates

02Disclosure timeline

February 15, 2018 CVE published
August 5, 2024 Record updated