PT-2010-3827 · Apache+2 · Apache Httpd+3

Published

2010-07-09

·

Updated

2022-05-14

·

CVE-2010-2227

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 5.5.0 through 5.5.29 Apache Tomcat versions 6.0.0 through 6.0.27
Description The issue arises from improper handling of an invalid Transfer-Encoding header, allowing remote attackers to cause a denial of service or obtain sensitive information by interfering with the recycling of a buffer. This can be triggered by a crafted header, leading to subsequent requests failing and/or information leaking between requests. The presence of a reverse proxy, such as Apache httpd 2.2, can mitigate this flaw as it should reject the invalid transfer encoding header.
Recommendations For Apache Tomcat versions 5.5.0 through 5.5.29, consider updating to a version that properly handles the Transfer-Encoding header to prevent denial of service and information leakage. For Apache Tomcat versions 6.0.0 through 6.0.27, consider updating to a version that properly handles the Transfer-Encoding header to prevent denial of service and information leakage. As a temporary workaround, consider placing Tomcat behind a reverse proxy, such as Apache httpd 2.2, to reject invalid transfer encoding headers and minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2227
DSA-2207-1
GHSA-CXG2-49RQ-8GCR
HPSBUX02579
HPSBUX02860
RHSA-2010:0580
RHSA-2010:0581
RHSA-2010:0582
RHSA-2010:0583
RHSA-2010:0584
RHSA-2010:0693
RHSA-2010_0580

Affected Products

Apache Tomcat
Apache Httpd
Hp-Ux
Red Hat