MGASA-2014-0110
Dashboard / Vulnerabilities / MGASA-2014-0110
Summary: Updated tomcat packages fix CVE-2014-0050
Details: Updated tomcat packages fix security vulnerability: It was discovered that the Apache Commons FileUpload package for Java could enter an infinite loop while processing a multipart request with a crafted Content-Type, resulting in a denial-of-service condition (CVE-2014-0050). Tomcat 7 includes an embedded copy of the Apache Commons FileUpload package, and was affected as well.
References: https://advisories.mageia.org/MGASA-2014-0110.html, http://seclists.org/fulldisclosure/2014/Feb/41, http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.52, https://bugs.mageia.org/show_bug.cgi?id=12899
Affected packages
Package
Name: tomcat
Purl: pkg:rpm/mageia/tomcat?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
