Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1093526 - (CVE-2014-0109) CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors
CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OO...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20140501,repor...
: Security
Depends On: 1095542 1095543 1095544 1095545 1095546 1095547 1095548 1095549 1166935 1166936 1166945 1167713
Blocks: 1059445 1082938 1093534 1108493 1210482
  Show dependency treegraph
 
Reported: 2014-05-01 21:40 EDT by Arun Babu Neelicattu
Modified: 2016-07-08 18:32 EDT (History)
54 users (show)

See Also:
Fixed In Version: cxf 2.6.14, cxf 2.7.11
Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-07-08 18:32:18 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0797 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 15:00:47 EDT
Red Hat Product Errata RHSA-2014:0798 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 15:16:02 EDT
Red Hat Product Errata RHSA-2014:0799 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 15:11:00 EDT
Red Hat Product Errata RHSA-2014:1351 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse/A-MQ 6.1.0 security update 2014-10-01 18:10:39 EDT
Red Hat Product Errata RHSA-2015:0850 normal SHIPPED_LIVE Important: Red Hat JBoss BRMS 6.1.0 update 2015-04-16 16:02:45 EDT
Red Hat Product Errata RHSA-2015:0851 normal SHIPPED_LIVE Important: Red Hat JBoss BPM Suite 6.1.0 update 2015-04-16 16:02:37 EDT
Red Hat Product Errata RHSA-2015:1009 normal SHIPPED_LIVE Important: Red Hat JBoss Portal 6.2.0 update 2015-05-14 15:14:47 EDT

  None (edit)
Description Arun Babu Neelicattu 2014-05-01 21:40:15 EDT
If content is posted to a SOAP endpoint with Content-Type text/html, CXF
creates an error message based on the input. This could potentially cause a
Out Of Memory (OOM) error on a large input, leading to a possible Denial of
Service attack.

Affected versions:
Apach CXF 2.6.x < 2.6.14
Apach CXF 2.7.x < 2.7.11

References:
http://cxf.apache.org/security-advisories.data/CVE-2014-0109.txt.asc

Upstream fix:
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=f8ed98e684c1a67a77ae8726db05a04a4978a445
Comment 2 Chess Hazlett 2014-05-07 21:58:06 EDT
Created cxf tracking bugs for this issue:

Affects: fedora-all [bug 1095542]
Comment 6 errata-xmlrpc 2014-06-26 11:01:07 EDT
This issue has been addressed in following products:

  Red Hat JBoss Enterprise Application Platform 6.2.4

Via RHSA-2014:0797 https://rhn.redhat.com/errata/RHSA-2014-0797.html
Comment 7 errata-xmlrpc 2014-06-26 11:18:03 EDT
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 5

Via RHSA-2014:0798 https://rhn.redhat.com/errata/RHSA-2014-0798.html
Comment 8 errata-xmlrpc 2014-06-26 12:17:56 EDT
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 6

Via RHSA-2014:0799 https://rhn.redhat.com/errata/RHSA-2014-0799.html
Comment 9 Martin Prpič 2014-09-29 07:59:35 EDT
IssueDescription:

A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.
Comment 10 errata-xmlrpc 2014-10-01 14:10:59 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse/A-MQ 6.1.0

Via RHSA-2014:1351 https://rhn.redhat.com/errata/RHSA-2014-1351.html
Comment 14 errata-xmlrpc 2015-04-16 12:04:14 EDT
This issue has been addressed in the following products:

  JBoss BPM Suite 6.1.0

Via RHSA-2015:0851 https://rhn.redhat.com/errata/RHSA-2015-0851.html
Comment 15 errata-xmlrpc 2015-04-16 12:08:48 EDT
This issue has been addressed in the following products:

  JBoss BRMS 6.1.0

Via RHSA-2015:0850 https://rhn.redhat.com/errata/RHSA-2015-0850.html
Comment 16 errata-xmlrpc 2015-05-14 11:17:48 EDT
This issue has been addressed in the following products:

  JBoss Portal 6.2.0

Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html

Note You need to log in before you can comment on or make changes to this bug.