Oval Definition:oval:com.ubuntu.cosmic:def:20190199000
Revision Date:2019-04-10Version:1
Title:CVE-2019-0199 on Ubuntu 18.10 (cosmic) - medium.
Description:The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-0199
Platform(s):Ubuntu 18.10
Product(s):
Definition Synopsis
  • Ubuntu 18.10 (cosmic) is installed.
  • AND Package Information
  • The 'tomcat8' package in cosmic was vulnerable but has been fixed (note: '8.5.39-1ubuntu1~18.10').
  • OR NOT While related to the CVE in some way, the 'tomcat9' package in cosmic is not affected (note: '9.0.16-3~18.10').
  • BACK