Bug 1093526 (CVE-2014-0109) - CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors
Summary: CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OO...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-0109
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1095542 1095543 1095544 1095545 1095546 1095547 1095548 1095549 1166935 1166936 1166945 1167713
Blocks: 1059445 1082938 1093534 1108493 1210482
TreeView+ depends on / blocked
 
Reported: 2014-05-02 01:40 UTC by Arun Babu Neelicattu
Modified: 2019-09-29 13:16 UTC (History)
54 users (show)

Fixed In Version: cxf 2.6.14, cxf 2.7.11
Doc Type: Bug Fix
Doc Text:
A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.
Clone Of:
Environment:
Last Closed: 2016-07-08 22:32:18 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0797 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:00:47 UTC
Red Hat Product Errata RHSA-2014:0798 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:16:02 UTC
Red Hat Product Errata RHSA-2014:0799 0 normal SHIPPED_LIVE Moderate: Red Hat JBoss Enterprise Application Platform 6.2.4 update 2014-06-26 19:11:00 UTC
Red Hat Product Errata RHSA-2014:1351 0 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse/A-MQ 6.1.0 security update 2014-10-01 22:10:39 UTC
Red Hat Product Errata RHSA-2015:0850 0 normal SHIPPED_LIVE Important: Red Hat JBoss BRMS 6.1.0 update 2015-04-16 20:02:45 UTC
Red Hat Product Errata RHSA-2015:0851 0 normal SHIPPED_LIVE Important: Red Hat JBoss BPM Suite 6.1.0 update 2015-04-16 20:02:37 UTC
Red Hat Product Errata RHSA-2015:1009 0 normal SHIPPED_LIVE Important: Red Hat JBoss Portal 6.2.0 update 2015-05-14 19:14:47 UTC

Description Arun Babu Neelicattu 2014-05-02 01:40:15 UTC
If content is posted to a SOAP endpoint with Content-Type text/html, CXF
creates an error message based on the input. This could potentially cause a
Out Of Memory (OOM) error on a large input, leading to a possible Denial of
Service attack.

Affected versions:
Apach CXF 2.6.x < 2.6.14
Apach CXF 2.7.x < 2.7.11

References:
http://cxf.apache.org/security-advisories.data/CVE-2014-0109.txt.asc

Upstream fix:
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=f8ed98e684c1a67a77ae8726db05a04a4978a445

Comment 2 Chess Hazlett 2014-05-08 01:58:06 UTC
Created cxf tracking bugs for this issue:

Affects: fedora-all [bug 1095542]

Comment 6 errata-xmlrpc 2014-06-26 15:01:07 UTC
This issue has been addressed in following products:

  Red Hat JBoss Enterprise Application Platform 6.2.4

Via RHSA-2014:0797 https://rhn.redhat.com/errata/RHSA-2014-0797.html

Comment 7 errata-xmlrpc 2014-06-26 15:18:03 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 5

Via RHSA-2014:0798 https://rhn.redhat.com/errata/RHSA-2014-0798.html

Comment 8 errata-xmlrpc 2014-06-26 16:17:56 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 6

Via RHSA-2014:0799 https://rhn.redhat.com/errata/RHSA-2014-0799.html

Comment 9 Martin Prpič 2014-09-29 11:59:35 UTC
IssueDescription:

A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.

Comment 10 errata-xmlrpc 2014-10-01 18:10:59 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse/A-MQ 6.1.0

Via RHSA-2014:1351 https://rhn.redhat.com/errata/RHSA-2014-1351.html

Comment 14 errata-xmlrpc 2015-04-16 16:04:14 UTC
This issue has been addressed in the following products:

  JBoss BPM Suite 6.1.0

Via RHSA-2015:0851 https://rhn.redhat.com/errata/RHSA-2015-0851.html

Comment 15 errata-xmlrpc 2015-04-16 16:08:48 UTC
This issue has been addressed in the following products:

  JBoss BRMS 6.1.0

Via RHSA-2015:0850 https://rhn.redhat.com/errata/RHSA-2015-0850.html

Comment 16 errata-xmlrpc 2015-05-14 15:17:48 UTC
This issue has been addressed in the following products:

  JBoss Portal 6.2.0

Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html


Note You need to log in before you can comment on or make changes to this bug.