When using the NIO connector with sendfile and HTTPS enabled, if a client breaks the connection while reading the response an infinite loop is entered leading to a denial of service. Source: Tomcat security pages. [1,2] [1] http://tomcat.apache.org/security-6.html [2] http://tomcat.apache.org/security-7.html
Created tomcat6 tracking bugs for this issue Affects: fedora-all [bug 883690]
Created tomcat tracking bugs for this issue Affects: fedora-16 [bug 883691]
tomcat-7.0.33-1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
Upstream bug report (including reproducer): https://issues.apache.org/bugzilla/show_bug.cgi?id=52858
This issue has been addressed in following products: JBoss Enterprise Web Server 2.0.0 Via RHSA-2013:0265 https://rhn.redhat.com/errata/RHSA-2013-0265.html
This issue has been addressed in following products: JBEWS 2 for RHEL 5 JBEWS 2 for RHEL 6 Via RHSA-2013:0266 https://rhn.redhat.com/errata/RHSA-2013-0266.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0623 https://rhn.redhat.com/errata/RHSA-2013-0623.html