[SECURITY] CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service)

Mark Thomas <[email protected]>
Newsgroups gmane.comp.apache.maven.announce,gmane.comp.security.full-disclosure,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.jakarta.tomcat.user,gmane.comp.security.bugtraq
Message-ID <530C7C42.9020204__28647.8472561159$1393327283$gmane$org@apache.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

CVE-2013-4322 Incomplete fix for CVE-2012-3544 (Denial of Service)

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
- - Apache Tomcat 8.0.0-RC1 to 8.0.0-RC5
- - Apache Tomcat 7.0.0 to 7.0.47
- - Apache Tomcat 6.0.0 to 6.0.37

Description:
The fix for CVE-2012-3544 was not complete. It did not cover the
following cases:
a) Chunk extensions were not limited
b) Whitespace after the : in a trailing header was not limited

Mitigation:
Users of affected versions should apply one of the following mitigations
- - Upgrade to Apache Tomcat 8.0.0-RC10 or later
  (8.0.0-RC6 to 8.0.0-RC9 contain the fix but were not released)
- - Upgrade to Apache Tomcat 7.0.50 or later
   (7.0.48 to 7.0.49 contain the fix but were not released)
- - Upgrade to Apache Tomcat 6.0.39 or later
   (6.0.38 contains the fix but was not released)

Credit:
This issue was partly identified by the Apache Tomcat security team and
party by Saran Neti of TELUS Security Labs.

References:
[1] http://tomcat.apache.org/security-8.html
[2] http://tomcat.apache.org/security-7.html
[3] http://tomcat.apache.org/security-6.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBAgAGBQJTDHxCAAoJEBDAHFovYFnnAtcP/0U8NgjCuhFBps1tAIqAa+ty
nLMYz3rgxHcY9ClWrJEBgGiIGb2wDQfylNsWR67PF/ue6yhLf+Bu5xs858Thr8V1
98ODkrQemNc9dcIdLJaRcSo05vzNCEN3v4vR9cpPpQpW8TB9y8L1HXmZEiGkM7ZD
nwa6E6GDJizkwR+3Qs11r3tAxNAHPn611EYajYLf7+4vPLqgV4GOx2/D7ol/wTm0
3BM15VZjTtlHqrtghUOdXYEzoXwR9BKMVoMtED3e++5i0vCuvvLToxTJ6jI/QjjE
UNm/hrfZK5ro3d+rzjOboLXIooAksK3A5UXxlvRi26ZgP3Nd0y8dN925WWfg2jXX
V1saa+42vpI6g4NcINIbFnBqfPdM/xKSIuyyXDmmTF2rUHQftcToLikzmSDZlm4c
edTyL+A4FcbEq8uymXwE/iA9KKa3PDcZheUw07YALp9JhFI6rfQT472cUavfNcGy
h0nxkHg2hU4yUBPm2PSyoTAokkjhDgRvGgX0hA3ljSi0SpHyTwPfoUIwUb+Emgmb
Vk00OJRJGtZs/GAL0TCd+LW96664Tx9oAqvgcLA3dZwLk94ivD5SC3Rl9xlyd4lF
cgLCOvzwxHcAh7syNd8orWjmyZsJ1vVqGoL1waK1hl1AQNxoJRfDixSlNjchpBxO
tCLvVC7UbgC0PFda+7kL
=Hzxr
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.