MGASA-2014-0149
Dashboard / Vulnerabilities / MGASA-2014-0149
MGASA-2014-0149
Summary: Updated tomcat package fixes security vulnerabilities
Details: Apache Tomcat 7.x before 7.0.50 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data (CVE-2013-4322). Apache Tomcat 7.x before 7.0.50 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (CVE-2013-4590).
References: https://advisories.mageia.org/MGASA-2014-0149.html, https://bugs.mageia.org/show_bug.cgi?id=12955, http://tomcat.apache.org/security-7.html
Affected packages
Package
Name: tomcat
Purl: pkg:rpm/mageia/tomcat?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
