Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2019-03-14 22:29
Updated : 2024-11-21 04:42
NVD link : CVE-2019-3833
Mitre link : CVE-2019-3833
CVE.ORG link : CVE-2019-3833
JSON object : View
Products Affected
openwsman_project
- openwsman
fedoraproject
- fedora
opensuse
- leap
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')