PT-2012-4798 · Apache+1 · Apache Tomcat+1
Saran Neti
·
Published
2012-12-31
·
Updated
2022-05-14
·
CVE-2012-3544
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 6.0.0 through 6.0.36
Apache Tomcat versions 7.0.0 through 7.0.29
Description
The issue allows remote attackers to cause a denial of service by streaming data due to improper handling of chunk extensions in chunked transfer coding.
Recommendations
For Apache Tomcat versions 6.0.0 through 6.0.36, update to version 6.0.37 or later.
For Apache Tomcat versions 7.0.0 through 7.0.29, update to version 7.0.30 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat
Suse