CVE-2014-0050
גבוהה 7.5
תיאור (מקור, אנגלית)
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CWE
- CWE-264, CWE-835
מוצרים מושפעים
oracle: retail applications; apache: commons fileupload; apache: tomcat
קישורים
- http://tomcat.apache.org/security-7.html PatchVendor Advisory
- http://tomcat.apache.org/security-8.html PatchVendor Advisory
- http://tomcat.apache.org/security-7.html PatchVendor Advisory
- http://tomcat.apache.org/security-8.html PatchVendor Advisory
- http://svn.apache.org/r1565143 Patch
- http://svn.apache.org/r1565143 Patch
- http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops… Exploit
- http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops… Exploit
- http://advisories.mageia.org/MGASA-2014-0110.html
- http://jvn.jp/en/jp/JVN14876762/index.html