Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3544

Опубликовано: 10 мая 2013
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

Отчет

This flaw affects Apache Tomcat 6.0.30 - 6.0.36 and 7.0.0 - 7.0.29. It does not affect JBoss Web.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5tomcat5Not affected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat JBoss Enterprise Application Platform 6jbosswebNot affected
Red Hat JBoss Enterprise Web Server 1eap-5Not affected
Red Hat JBoss Enterprise Web Server 1tomcat5Not affected
Red Hat JBoss Enterprise Web Server 1tomcat6Will not fix
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-daemon-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-daemon-jsvc-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5apache-commons-pool-eap6FixedRHSA-2013:101103.07.2013
Red Hat JBoss Enterprise Web Server 2 for RHEL 5dom4jFixedRHSA-2013:101103.07.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=961783tomcat: Limited DoS in chunked transfer encoding input filter

EPSS

Процентиль: 97%
0.38137
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

nvd
около 12 лет назад

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

debian
около 12 лет назад

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properl ...

github
около 3 лет назад

Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions

suse-cvrf
около 12 лет назад

Security update for tomcat6

EPSS

Процентиль: 97%
0.38137
Средний

4.3 Medium

CVSS2