Bug 1072776 (CVE-2014-0075)
Summary: | CVE-2014-0075 Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | David Jorm <djorm> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | anil.saldhana, bdawidow, ccoleman, cdewolf, chazlett, chuffman, csutherl, darran.lofthouse, dmcphers, drieden, epp-bugs, erich, fnasser, grocha, huwang, ivan.afonichev, jawilson, jclere, jcoleman, jdg-bugs, jdoyle, jialiu, jkurik, jokerman, jpallich, kconner, kejohnso, krzysztof.daniel, lgao, lmeyer, mjc, mmccomas, mmcgrath, mmiura, mrobson, mweiler, myarboro, nobody+bgollahe, ohudlick, pcheung, pgier, pslavice, rhq-maint, rsvoboda, security-response-team, soa-p-jira, spinder, theute, ttarrant, vtunka, weli |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | tomcat 7.0.53, tomcat 6.0.41 | Doc Type: | Bug Fix |
Doc Text: |
It was discovered that JBoss Web / Apache Tomcat did not limit the length of chunk sizes when using chunked transfer encoding. A remote attacker could use this flaw to perform a denial of service attack against JBoss Web / Apache Tomcat by streaming an unlimited quantity of data, leading to excessive consumption of server resources.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 02:31:51 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1102669, 1102670, 1102671, 1102672, 1102673, 1102674, 1102675, 1102676, 1102677, 1102678, 1102679, 1102680, 1102681, 1102691, 1102707, 1102709, 1102711, 1102713, 1102714, 1102716, 1102717, 1102718, 1102719, 1102720, 1102721, 1102722, 1102725, 1105089, 1105092, 1113319, 1113326, 1113339, 1160690 | ||
Bug Blocks: | 1072779, 1079805, 1082938, 1097027, 1103878, 1105099, 1105100, 1105275, 1108465, 1120975, 1181883, 1182400, 1182419, 1200191 |
Description
David Jorm
2014-03-05 08:24:52 UTC
Upstream patch commits: Tomcat 6: http://svn.apache.org/viewvc?view=revision&revision=1579262 Tomcat 7: http://svn.apache.org/viewvc?view=revision&revision=1578341 Acknowledgements: This issue was discovered by David Jorm of Red Hat Product Security. This issue has been addressed in following products: Red Hat Enterprise Linux 7 Via RHSA-2014:0827 https://rhn.redhat.com/errata/RHSA-2014-0827.html This issue has been addressed in following products: JBoss Enterprise Web Server 2.0.1 Via RHSA-2014:0836 https://rhn.redhat.com/errata/RHSA-2014-0836.html This issue has been addressed in following products: JBEWS 2 for RHEL 5 JBEWS 2 for RHEL 6 Via RHSA-2014:0835 https://rhn.redhat.com/errata/RHSA-2014-0835.html This issue has been addressed in following products: JBoss Enterprise Web Server 2.0.1 Via RHSA-2014:0833 https://rhn.redhat.com/errata/RHSA-2014-0833.html This issue has been addressed in following products: JBEWS 2 for RHEL 5 JBEWS 2 for RHEL 6 Via RHSA-2014:0834 https://rhn.redhat.com/errata/RHSA-2014-0834.html This issue has been addressed in following products: JBEAP 6.2 for RHEL 6 JBEAP 6.2 for RHEL 5 Via RHSA-2014:0843 https://rhn.redhat.com/errata/RHSA-2014-0843.html This issue has been addressed in following products: JBoss Enterprise Application Platform 6.2.4 Via RHSA-2014:0842 https://rhn.redhat.com/errata/RHSA-2014-0842.html Statement: This issue does affect JBossWeb as shipped in Red Hat JBoss Enterprise Application Platform 5. Red Hat Product Security has rated this issue as having Moderate security impact. Red Hat JBoss Enterprise Application Platform 5 is currently in reduced support phase (Phase 2: Maintenance Support), receiving only Critical and Important security updates, hence this issue is not currently planned to be addressed in future updates for Red Hat Enterprise Application Platform 5. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/ and the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2014:0865 https://rhn.redhat.com/errata/RHSA-2014-0865.html This issue has been addressed in following products: JBoss Data Grid 6.3.0 Via RHSA-2014:0895 https://rhn.redhat.com/errata/RHSA-2014-0895.html IssueDescription: It was discovered that JBoss Web / Apache Tomcat did not limit the length of chunk sizes when using chunked transfer encoding. A remote attacker could use this flaw to perform a denial of service attack against JBoss Web / Apache Tomcat by streaming an unlimited quantity of data, leading to excessive consumption of server resources. This issue has been addressed in following products: Red Hat JBoss Operations Network 3.2.3 Via RHSA-2014:1149 https://rhn.redhat.com/errata/RHSA-2014-1149.html This issue has been addressed in the following products: Red Hat JBoss BRMS 6.0.3 Via RHSA-2015:0235 https://rhn.redhat.com/errata/RHSA-2015-0235.html This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.0.3 Via RHSA-2015:0234 https://rhn.redhat.com/errata/RHSA-2015-0234.html tomcat-7.0.59-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in the following products: JBoss Data Virtualization 6.1.0 Via RHSA-2015:0675 https://rhn.redhat.com/errata/RHSA-2015-0675.html This issue has been addressed in the following products: Red Hat JBoss Fuse Service Works 6.0.0 Via RHSA-2015:0720 https://rhn.redhat.com/errata/RHSA-2015-0720.html This issue has been addressed in the following products: Red Hat JBoss Data Virtualization 6.0.0 Via RHSA-2015:0765 https://rhn.redhat.com/errata/RHSA-2015-0765.html This issue has been addressed in the following products: JBoss Portal 6.2.0 Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html |