APP: JBoss Remoting Denial of Service

This signature detects attempts to exploit a known vulnerability against JBoss Remoting. A successful attack can result in a denial-of-service condition.

Extended Description

A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial of service via high CPU caused by an infinite loop.

Affected Products

Jboss jboss-remoting

Short Name
APP:JBOSS-REMOTING-DOS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2018-1041 Denial JBoss Remoting Service of
Release Date
09/26/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
Port
TCP/4447,9999
False Positive
Unknown
Vendors

Jboss

CVSS Score

5.0

Found a potential security threat?