[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2897-1 tomcat7 -- tomcat7

ID: oval:org.secpod.oval:def:601258Date: (C)2014-07-21   (M)2022-10-10
Class: PATCHFamily: unix




Multiple security issues were found in the Tomcat servlet and JSP engine: CVE-2013-2067 FORM authentication associates the most recent request requiring authentication with the current session. By repeatedly sending a request for an authenticated resource while the victim is completing the login form, an attacker could inject a request that would be executed using the victim"s credentials. CVE-2013-2071 A runtime exception in AsyncListener.onComplete prevents the request from being recycled. This may expose elements of a previous request to a current request. CVE-2013-4286 Reject requests with multiple content-length headers or with a content-length header when chunked encoding is being used. CVE-2013-4322 When processing a request submitted using the chunked transfer encoding, Tomcat ignored but did not limit any extensions that were included. This allows a client to perform a limited denial of service. by streaming an unlimited amount of data to the server. CVE-2014-0050 Multipart requests with a malformed Content-Type header could trigger an infinite loop causing a denial of service.

Platform:
Debian 7.0
Product:
tomcat7
Reference:
DSA-2897-1
CVE-2013-2067
CVE-2013-2071
CVE-2013-4286
CVE-2013-4322
CVE-2014-0050
CVE    5
CVE-2014-0050
CVE-2013-2067
CVE-2013-2071
CVE-2013-4322
...
CPE    2
cpe:/o:debian:debian_linux:7.x
cpe:/a:apache:tomcat7

© SecPod Technologies