CVE Vulnerabilities

CVE-2011-0534

Published: Feb 10, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache7.0.0 (including)7.0.0 (including)
TomcatApache7.0.1 (including)7.0.1 (including)
TomcatApache7.0.2 (including)7.0.2 (including)
TomcatApache7.0.3 (including)7.0.3 (including)
TomcatApache7.0.4 (including)7.0.4 (including)
TomcatApache7.0.5 (including)7.0.5 (including)
TomcatApache7.0.6 (including)7.0.6 (including)
JBEWS 1.0 for RHEL 4RedHattomcat6-0:6.0.24-11.patch_03.ep5.el4*
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-24.el6_0*
Red Hat JBoss Enterprise Web Server 1 for RHEL 5RedHattomcat6-0:6.0.24-11.patch_03.ep5.el5*
Red Hat JBoss Web Server 1.0RedHat*
Tomcat6Ubuntukarmic*
Tomcat6Ubuntulucid*
Tomcat6Ubuntumaverick*

References