PT-2012-4798 · Apache+1 · Apache Tomcat+1

Saran Neti

·

Published

2012-12-31

·

Updated

2022-05-14

·

CVE-2012-3544

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.0 through 6.0.36 Apache Tomcat versions 7.0.0 through 7.0.29
Description The issue allows remote attackers to cause a denial of service by streaming data due to improper handling of chunk extensions in chunked transfer coding.
Recommendations For Apache Tomcat versions 6.0.0 through 6.0.36, update to version 6.0.37 or later. For Apache Tomcat versions 7.0.0 through 7.0.29, update to version 7.0.30 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3544
DSA-2725-1
DSA-2897-1
GHSA-QFXV-3PPC-7QG5
MGASA-2014-0082
RHSA-2013:1011
RHSA-2013:1012
SUSE-SU-2014_1015-1
USN-1841-1

Affected Products

Apache Tomcat
Suse