Public bug reported:

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6,
9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1
processor after the upgrade to HTTP/2. If a sufficient number of such
requests were made, an OutOfMemoryException could occur leading to a
denial of service.


https://nvd.nist.gov/vuln/detail/CVE-2020-13934

** Affects: tomcat9 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1888848

Title:
  https://nvd.nist.gov/vuln/detail/CVE-2020-13934

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tomcat9/+bug/1888848/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to