vulnerability

FreeBSD: VID-6a72eff7-ccd6-11ea-9172-4c72b94353b5 (CVE-2020-13934): Apache Tomcat -- Multiple Vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jul 23, 2020
Added
Jul 24, 2020
Modified
Dec 10, 2025

Description

The Apache Software Foundation reports: An h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service. The payload length in a WebSocket frame was not correctly validated. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service. A specially crafted sequence of HTTP/2 requests could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.

Solutions

freebsd-upgrade-package-tomcat7freebsd-upgrade-package-tomcat85freebsd-upgrade-package-tomcat9freebsd-upgrade-package-tomcat-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.