USN-1429-1: Jetty vulnerability
26 April 2012
Jetty could be made to hang or crash if it received specially crafted network traffic.
Releases
Packages
- jetty - Java servlet engine and webserver
Details
It was discovered that Jetty computed hash values for form parameters
without restricting the ability to trigger hash collisions predictably.
This could allow a remote attacker to cause a denial of service by
sending many crafted parameters.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.04
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.