[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-4534Date: (C)2012-12-20   (M)2023-12-22


org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1027836
http://archives.neohapsis.com/archives/bugtraq/2012-12/0043.html
BID-56813
SECUNIA-57126
HPSBMU02873
HPSBST02955
IAVM:2012-B-0110
RHSA-2013:0623
SSRT101139
SSRT101182
USN-1685-1
http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/tomcat/util/net/NioEndpoint.java?r1=1340218&r2=1340217&pathrev=1340218
http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/webapps/docs/changelog.xml?r1=1340218&r2=1340217&pathrev=1340218
http://svn.apache.org/viewvc?view=revision&revision=1340218
http://tomcat.apache.org/security-6.html
http://tomcat.apache.org/security-7.html
https://issues.apache.org/bugzilla/show_bug.cgi?id=52858
openSUSE-SU-2013:0161
openSUSE-SU-2013:0170
openSUSE-SU-2013:0192
oval:org.mitre.oval:def:19398

CPE    70
cpe:/a:apache:tomcat:6.0.6:alpha
cpe:/a:apache:tomcat:6.0
cpe:/a:apache:tomcat:6.0.18
cpe:/a:apache:tomcat:7.0.0:beta
...
CWE    1
CWE-399
OVAL    7
oval:org.secpod.oval:def:8234
oval:org.secpod.oval:def:701135
oval:org.secpod.oval:def:202639
oval:org.secpod.oval:def:601073
...

© SecPod Technologies