CVE-2010-4265
Summary
| CVE | CVE-2010-4265 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-30 21:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch. NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:N/AC:H/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:H/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp01 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp02 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp03 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp04 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp05 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp06 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp07 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp08 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 4.3.0 | cp09 | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Remoting | 2.2.0 | All | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp10 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp11 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp2 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp4 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp7 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.2 | sp8 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.3 | All | All | All |
| Application | Redhat | Jboss Remoting | 2.2.3 | sp1 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.3 | sp2 | All | All |
| Application | Redhat | Jboss Remoting | 2.2.3 | sp3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Login server redirect | af854a3a-2127-422b-91ae-364da2661108 | issues.jboss.org | |
| JBoss Enterprise Application Platform Remoting Bug Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| 660623 – (CVE-2010-4265) CVE-2010-4265 jboss-remoting: missing fix for CVE-2010-3862 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [#JBREM-1261] Prevent DOS attack on BisocketServerInvoker$SecondaryServerSocketThread - JBoss Issue Tracker | af854a3a-2127-422b-91ae-364da2661108 | issues.jboss.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.