PT-2010-3827 · Apache+2 · Apache Httpd+3
Published
2010-07-09
·
Updated
2022-05-14
·
CVE-2010-2227
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 5.5.0 through 5.5.29
Apache Tomcat versions 6.0.0 through 6.0.27
Description
The issue arises from improper handling of an invalid Transfer-Encoding header, allowing remote attackers to cause a denial of service or obtain sensitive information by interfering with the recycling of a buffer. This can be triggered by a crafted header, leading to subsequent requests failing and/or information leaking between requests. The presence of a reverse proxy, such as Apache httpd 2.2, can mitigate this flaw as it should reject the invalid transfer encoding header.
Recommendations
For Apache Tomcat versions 5.5.0 through 5.5.29, consider updating to a version that properly handles the Transfer-Encoding header to prevent denial of service and information leakage.
For Apache Tomcat versions 6.0.0 through 6.0.27, consider updating to a version that properly handles the Transfer-Encoding header to prevent denial of service and information leakage.
As a temporary workaround, consider placing Tomcat behind a reverse proxy, such as Apache httpd 2.2, to reject invalid transfer encoding headers and minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Apache Httpd
Hp-Ux
Red Hat