Red Hat JBoss Enterprise Application Platform and JBoss Enterprise Web Platform contain a flaw that may allow a remote denial of service. The issue is triggered when the 'org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run' method in JBoss Remoting allows remote attackers to establish a bisocket control connection TCP session and then not send any application daa, resulting in a denial of service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Upgrade JBoss Remoting to version 2.2.3.SP4 or 2.5.3.SP2 or higher, as it has been reported to fix this vulnerability. In addition, Red Hat has released patches for other affected products.