CVE-2016-3092
🟡 Monitoruj
Klasa MultipartStream w Apache Commons Fileupload umożliwia atakującym zdalne wywołanie odmowy usługi.
CVSS
7.5
EPSS
35.9%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 35.9% |
| Opublikowano (NVD) | 2016-07-04 22:59:04 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 18:17:07 UTC |
Referencje
- http://jvn.jp/en/jp/JVN89379547/index.html ([email protected]) [Vendor Advisory]
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121 ([email protected]) [VDB Entry, Vendor Advisory]
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html ([email protected])
- http://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3E ([email protected]) [Mailing List]
- http://rhn.redhat.com/errata/RHSA-2016-2068.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2069.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2070.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2071.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2072.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2599.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2807.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2016-2808.html ([email protected])
- http://rhn.redhat.com/errata/RHSA-2017-0457.html ([email protected])
- http://svn.apache.org/viewvc?view=revision&revision=1743480 ([email protected])
- http://svn.apache.org/viewvc?view=revision&revision=1743722 ([email protected]) [Vendor Advisory]
- http://svn.apache.org/viewvc?view=revision&revision=1743738 ([email protected]) [Vendor Advisory]
- http://svn.apache.org/viewvc?view=revision&revision=1743742 ([email protected]) [Vendor Advisory]
- http://tomcat.apache.org/security-7.html ([email protected]) [Vendor Advisory]
- http://tomcat.apache.org/security-8.html ([email protected]) [Vendor Advisory]
- http://tomcat.apache.org/security-9.html ([email protected]) [Vendor Advisory]
- http://www.debian.org/security/2016/dsa-3609 ([email protected]) [Third Party Advisory]
- http://www.debian.org/security/2016/dsa-3611 ([email protected]) [Third Party Advisory]
- http://www.debian.org/security/2016/dsa-3614 ([email protected]) [Third Party Advisory]
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html ([email protected])
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html ([email protected])
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html ([email protected])
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html ([email protected])
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html ([email protected])
- http://www.securityfocus.com/bid/91453 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1036427 ([email protected])
- http://www.securitytracker.com/id/1036900 ([email protected])
- http://www.securitytracker.com/id/1037029 ([email protected])
- http://www.securitytracker.com/id/1039606 ([email protected])
- http://www.ubuntu.com/usn/USN-3024-1 ([email protected]) [Third Party Advisory]
- http://www.ubuntu.com/usn/USN-3027-1 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:0455 ([email protected])
- https://access.redhat.com/errata/RHSA-2017:0456 ([email protected])
- https://bugzilla.redhat.com/show_bug.cgi?id=1349468 ([email protected]) [Issue Tracking]
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371 ([email protected]) [Patch, Permissions Required, Third Party Advisory]
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289840 ([email protected])
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759 ([email protected])
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://security.gentoo.org/glsa/201705-09 ([email protected])
- https://security.gentoo.org/glsa/202107-39 ([email protected])
- https://security.netapp.com/advisory/ntap-20190212-0001/ ([email protected])
- https://www.oracle.com/security-alerts/cpuapr2020.html ([email protected])
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ([email protected])