A denial of service flaw was found in the way chunked transfer encoding input filter of Apache Tomcat, an Apache Servlet/JSP Engine, processed CRLF sequences at the end of data chunks in certain circumstances. When the chunked transfer encoding was enabled, a remote attacker could issue a specially-crafted request that, when processed would lead to (limited) denial of service of the Apache Tomcat server.
Relevant upstream patch:
* for Apache Tomcat 6.x:
http://svn.apache.org/viewvc?view=revision&revision=1476592
* for Apache Tomcat 7:x:
http://svn.apache.org/viewvc?view=rev&rev=1378702http://svn.apache.org/viewvc?view=rev&rev=1378921
This issue did NOT affect the versions of the tomcat package, as shipped with Fedora release of 17 and 18 (the current versions already contain aforementioned upstream patch).
--
This issue affects the versions of the tomcat6 package, as shipped with Fedora release of 17 and 18. Please schedule an update.