Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.803782
Categoría:Denial of Service
Título:Apache Tomcat NIO Connector Denial of Service Vulnerability
Resumen:Apache Tomcat is prone to a denial of service (DoS) vulnerability.
Descripción:Summary:
Apache Tomcat is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
Tomcat did not enforce the maxHttpHeaderSize limit while parsing the request
line in the NIO HTTP connector. A specially crafted request could trigger an DoS via an OutOfMemoryError.

Vulnerability Impact:
Successful exploitation will allow remote attackers to trigger a
denial-of-service condition in the affected software.

Affected Software/OS:
Apache Tomcat version 6.0.x before 6.0.32
Apache Tomcat version 7.0.x before 7.0.8

Solution:
Upgrade Apache Tomcat version to 6.0.32, 7.0.8 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-0534
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
BugTraq ID: 46164
http://www.securityfocus.com/bid/46164
Bugtraq: 20110205 [SECURITY] CVE-2011-0534 Apache Tomcat DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/516214/100/0/threaded
Debian Security Information: DSA-2160 (Google Search)
http://www.debian.org/security/2011/dsa-2160
HPdes Security Advisory: HPSBST02955
http://marc.info/?l=bugtraq&m=139344343412337&w=2
http://osvdb.org/70809
http://www.securitytracker.com/id?1025027
http://secunia.com/advisories/43192
http://secunia.com/advisories/45022
http://secunia.com/advisories/57126
http://securityreason.com/securityalert/8074
SuSE Security Announcement: SUSE-SR:2011:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
http://www.vupen.com/english/advisories/2011/0293
XForce ISS Database: tomcat-nio-connector-dos(65162)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65162
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.