[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2014-0686 -- Oracle tomcat

ID: oval:org.secpod.oval:def:1500647Date: (C)2014-08-22   (M)2023-11-10
Class: PATCHFamily: unix




It was found that a fix for a previous security flaw introduced a regression that could cause a denial of service in Tomcat 7. A remote attacker could use this flaw to consume an excessive amount of CPU on the Tomcat server by sending a specially crafted request to that server. It was found that when Tomcat 7 processed a series of HTTP requests in which at least one request contained either multiple content-length headers, or one content-length header with a chunked transfer-encoding header, Tomcat would incorrectly handle the request. A remote attacker could use this flaw to poison a web cache, perform cross-site scripting (XSS) attacks, or obtain sensitive information from other requests.

Platform:
Oracle Linux 7
Product:
tomcat
Reference:
ELSA-2014-0686
CVE-2013-4286
CVE-2014-0186
CVE-2013-4322
CVE    3
CVE-2014-0186
CVE-2013-4322
CVE-2013-4286
CPE    187
cpe:/a:apache:tomcat:3.3.1a
cpe:/a:apache:tomcat:4.1.10
cpe:/a:apache:tomcat:4.1.15
cpe:/a:apache:tomcat:4.1.12
...

© SecPod Technologies