Описание
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
A denial of service flaw was found in the way Apache Commons FileUpload, which is embedded in Tomcat and JBoss Web, handled small-sized buffers used by MultipartStream. A remote attacker could use this flaw to create a malformed Content-Type header for a multipart request, causing Tomcat to enter an infinite loop when processing such an incoming request.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat BPM Suite 6 | commons-fileupload | Affected | ||
Red Hat Developer Toolset 2.0 | devtoolset-2-tomcat | Not affected | ||
Red Hat Enterprise Linux 5 | jakarta-commons-fileupload | Under investigation | ||
Red Hat Enterprise Linux 7 | tomcat | Not affected | ||
Red Hat JBoss BRMS 5 | commons-fileupload | Will not fix | ||
Red Hat JBoss BRMS 6 | commons-fileupload | Affected | ||
Red Hat JBoss Data Grid 6 | jbossweb | Not affected | ||
Red Hat JBoss Data Virtualization 6 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | commons-fileupload | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | eap-4 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as use ...
Уязвимость файла MultipartStream.java библиотеки Apache Commons FileUpload, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2