Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2227

Опубликовано: 08 июл. 2010
Источник: redhat
CVSS2: 6.4
EPSS Высокий

Описание

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 7.2OtherAffected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat Satellite 5.0ServerAffected
Red Hat Satellite 5.1ServerAffected
Red Hat Satellite 5.2ServerAffected
Red Hat Satellite 5.3ServerAffected
JBEAP 4.2.0 for RHEL 4jbosswebFixedRHSA-2010:058402.08.2010
JBEAP 4.2.0 for RHEL 5jbosswebFixedRHSA-2010:058402.08.2010
JBEWS 1.0 for RHEL 4tomcat5FixedRHSA-2010:058102.08.2010
JBEWS 1.0 for RHEL 4tomcat6FixedRHSA-2010:058102.08.2010

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=612799tomcat: information leak vulnerability in the handling of 'Transfer-Encoding' header

EPSS

Процентиль: 99%
0.80885
Высокий

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

nvd
почти 15 лет назад

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

debian
почти 15 лет назад

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 be ...

github
около 3 лет назад

Apache Tomcat does not properly handle an invalid Transfer-Encoding header

oracle-oval
почти 15 лет назад

ELSA-2010-0580: tomcat5 security update (IMPORTANT)

EPSS

Процентиль: 99%
0.80885
Высокий

6.4 Medium

CVSS2