logo

Database

Lack of data validation In org.apache.tomcat:tomcat

Description

Improper Input Validation in Apache Tomcat java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/tomcat/commit/593a2447e6ebe465585cfa07e93b5635dffa1c702. https://bugzilla.redhat.com/show_bug.cgi?id=11091963. https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E4. https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E5. https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E6. https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E7. https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E8. https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E9. https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E10. https://source.jboss.org/changelog/JBossWeb?cs=245511. http://advisories.mageia.org/MGASA-2015-0081.html12. http://archives.neohapsis.com/archives/bugtraq/2015-02/0067.html13. http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150282.html14. http://marc.info/?l=bugtraq&m=143393515412274&w=215. http://marc.info/?l=bugtraq&m=143403519711434&w=216. http://rhn.redhat.com/errata/RHSA-2015-0675.html17. http://rhn.redhat.com/errata/RHSA-2015-0720.html18. http://rhn.redhat.com/errata/RHSA-2015-0765.html19. http://rhn.redhat.com/errata/RHSA-2015-0983.html20. http://rhn.redhat.com/errata/RHSA-2015-0991.html21. http://svn.apache.org/viewvc?view=revision&revision=160098422. http://tomcat.apache.org/security-6.html23. http://tomcat.apache.org/security-7.html24. http://tomcat.apache.org/security-8.html25. http://www.debian.org/security/2016/dsa-344726. http://www.debian.org/security/2016/dsa-353027. http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html28. http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html29. http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html30. http://www.ubuntu.com/usn/USN-2654-131. http://www.ubuntu.com/usn/USN-2655-1
FLAT-QW4F4 – Vulnerability | Fluid Attacks Database