Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11150
Category:Denial of Service
Title:Tomcat servlet engine MS/DOS device names denial of service
Summary:It was possible to freeze or crash Windows or the web server; by reading a thousand of times a MS/DOS device through Tomcat servlet engine, using a file name; like /examples/servlet/AUX.
Description:Summary:
It was possible to freeze or crash Windows or the web server
by reading a thousand of times a MS/DOS device through Tomcat servlet engine, using a file name
like /examples/servlet/AUX.

Vulnerability Impact:
A cracker may use this flaw to make your system crash
continuously, preventing you from working properly.

Affected Software/OS:
Apache Tomcat 3.3

Apache Tomcat 4.0.4

All versions prior to 4.1.x may be affected as well.

Apache Tomcat 4.1.10 (and probably higher) is not affected.

Microsoft Windows 2000

Microsoft Windows NT may be affected as well.

Solution:
Upgrade your Apache Tomcat web server to version 4.1.10.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0045
XForce ISS Database: jakarta-tomcat-msdos-dos(12102)
https://exchange.xforce.ibmcloud.com/vulnerabilities/12102
CopyrightCopyright (C) 2002 Michel Arboi

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.