MGASA-2014-0148
Dashboard / Vulnerabilities / MGASA-2014-0148
MGASA-2014-0148
Summary: Updated tomcat package fixes security vulnerabilities
Details: Apache Tomcat 7.x before 7.0.47, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header (CVE-2013-4286). Apache Tomcat 7.x before 7.0.50 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data (CVE-2013-4322). Apache Tomcat 7.x before 7.0.50 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (CVE-2013-4590).
References: https://advisories.mageia.org/MGASA-2014-0148.html, https://bugs.mageia.org/show_bug.cgi?id=12955, http://tomcat.apache.org/security-7.html
Affected packages
Package
Name: tomcat
Purl: pkg:rpm/mageia/tomcat?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
