PT-2014-1446 · Apache+4 · Apache Tomcat+4

Publicado

2014-03-27

·

Atualizado

2022-05-14

·

CVE-2014-0075

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.0 through 6.0.39 Apache Tomcat versions 7.0.0 through 7.0.52 Apache Tomcat versions 8.0.0 through 8.0.3
Description The issue allows remote attackers to cause a denial of service through a malformed chunk size in chunked transfer coding of a request during data transmission. This can lead to excessive resource consumption. The problem is related to an integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java. It was possible to craft a malformed chunk size as part of a chunked request, enabling an unlimited amount of data to be streamed to the server and bypassing size limits enforced on a request, thus enabling a denial of service attack.
Recommendations For Apache Tomcat versions 6.0.0 through 6.0.39, update to version 6.0.40 or later. For Apache Tomcat versions 7.0.0 through 7.0.52, update to version 7.0.53 or later. For Apache Tomcat versions 8.0.0 through 8.0.3, update to version 8.0.4 or later.

Correção

DoS

Integer Overflow

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00408
CESA-2014_0865
CVE-2014-0075
DSA-3447-1
DSA-3530-1
GHSA-475F-74WP-PQV5
HPSBUX03102
HPSBUX03150
MGASA-2014-0268
RHSA-2014:0827
RHSA-2014:0834
RHSA-2014:0835
RHSA-2014:0843
RHSA-2014:0865
RHSA-2014_0827
RHSA-2014_0865
USN-2302-1

Produtos afetados

Apache Tomcat
Centos
Hp-Ux
Red Hat
Ubuntu