CVE-2012-3544
⚪ Do wiadomości
Błąd w Apache Tomcat umożliwia zdalnym atakującym wywołanie odmowy usługi.
CVSS
5.0
EPSS
11.0%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 11.0% |
| Opublikowano (NVD) | 2013-06-01 14:21:05 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 20:17:03 UTC |
Referencje
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0042.html ([email protected])
- http://seclists.org/fulldisclosure/2014/Dec/23 ([email protected])
- http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/coyote/http11/filters/ChunkedInputFilter.java?r1=1476592&r2=1476591&pathrev=1476592 ([email protected]) [Patch]
- http://svn.apache.org/viewvc?view=revision&revision=1378702 ([email protected]) [Patch]
- http://svn.apache.org/viewvc?view=revision&revision=1378921 ([email protected]) [Patch]
- http://svn.apache.org/viewvc?view=revision&revision=1476592 ([email protected]) [Patch]
- http://tomcat.apache.org/security-6.html ([email protected]) [Vendor Advisory]
- http://tomcat.apache.org/security-7.html ([email protected]) [Vendor Advisory]
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html ([email protected])
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html ([email protected])
- http://www.securityfocus.com/archive/1/534161/100/0/threaded ([email protected])
- http://www.securityfocus.com/bid/59797 ([email protected])
- http://www.securityfocus.com/bid/64758 ([email protected])
- http://www.ubuntu.com/usn/USN-1841-1 ([email protected])
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html ([email protected])
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E ([email protected])