CVE Vulnerabilities

CVE-2011-0534

Published: Feb 10, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 7.0.0 (including) 7.0.0 (including)
Tomcat Apache 7.0.1 (including) 7.0.1 (including)
Tomcat Apache 7.0.2 (including) 7.0.2 (including)
Tomcat Apache 7.0.3 (including) 7.0.3 (including)
Tomcat Apache 7.0.4 (including) 7.0.4 (including)
Tomcat Apache 7.0.5 (including) 7.0.5 (including)
Tomcat Apache 7.0.6 (including) 7.0.6 (including)
JBEWS 1.0 for RHEL 4 RedHat tomcat6-0:6.0.24-11.patch_03.ep5.el4 *
Red Hat Enterprise Linux 6 RedHat tomcat6-0:6.0.24-24.el6_0 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat6-0:6.0.24-11.patch_03.ep5.el5 *
Red Hat JBoss Web Server 1.0 RedHat *
Tomcat6 Ubuntu karmic *
Tomcat6 Ubuntu lucid *
Tomcat6 Ubuntu maverick *

References