PT-2012-4222 · Apache+2 · Apache Tomcat+2
Josh Spiewak
·
Published
2012-10-19
·
Updated
2017-09-19
·
CVE-2012-2733
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 6.0.0 through 6.0.35
Apache Tomcat versions 7.0.0 through 7.0.27
Description
The issue is related to the HTTP NIO connector, where the request-header size is not properly restricted. This allows remote attackers to cause a denial of service by consuming memory via a large amount of header data. The checks that limited the permitted size of request headers were implemented too late in the request parsing process, enabling a malicious user to trigger an OutOfMemoryError by sending a single request with very large headers.
Recommendations
For Apache Tomcat versions 6.0.0 through 6.0.35, update to version 6.0.36 or later.
For Apache Tomcat versions 7.0.0 through 7.0.27, update to version 7.0.28 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Hp-Ux
Suse