Upstream information
Description
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.NVD CVSS v2 Base Score: 2.6 (AV:N/AC:H/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 794548 SUSE Security Advisories:- openSUSE-SU-2013:0161-1, published Wed, 23 Jan 2013 14:06:32 +0100 (CET)
- openSUSE-SU-2013:0170-1, published Wed, 23 Jan 2013 14:06:54 +0100 (CET)
- openSUSE-SU-2013:0192-1, published Wed, 23 Jan 2013 20:04:50 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Manager 1.2 for SLE 11 SP1 |
| Builds SAT Patch Nr: 7209 |
| SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP2 for VMware |
| Builds SAT Patch Nr: 7208 |
