PT-2014-1446 · Apache+4 · Apache Tomcat+4

Published

2014-03-27

·

Updated

2022-05-14

·

CVE-2014-0075

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.0 through 6.0.39 Apache Tomcat versions 7.0.0 through 7.0.52 Apache Tomcat versions 8.0.0 through 8.0.3
Description The issue allows remote attackers to cause a denial of service through a malformed chunk size in chunked transfer coding of a request during data transmission. This can lead to excessive resource consumption. The problem is related to an integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java. It was possible to craft a malformed chunk size as part of a chunked request, enabling an unlimited amount of data to be streamed to the server and bypassing size limits enforced on a request, thus enabling a denial of service attack.
Recommendations For Apache Tomcat versions 6.0.0 through 6.0.39, update to version 6.0.40 or later. For Apache Tomcat versions 7.0.0 through 7.0.52, update to version 7.0.53 or later. For Apache Tomcat versions 8.0.0 through 8.0.3, update to version 8.0.4 or later.

Fix

DoS

Integer Overflow

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00408
CESA-2014_0865
CVE-2014-0075
DSA-3447-1
DSA-3530-1
GHSA-475F-74WP-PQV5
HPSBUX03102
HPSBUX03150
MGASA-2014-0268
RHSA-2014:0827
RHSA-2014:0834
RHSA-2014:0835
RHSA-2014:0843
RHSA-2014:0865
RHSA-2014_0827
RHSA-2014_0865
USN-2302-1

Affected Products

Apache Tomcat
Centos
Hp-Ux
Red Hat
Ubuntu