Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 7.0.0 (including) | 7.0.0 (including) |
Tomcat | Apache | 7.0.1 (including) | 7.0.1 (including) |
Tomcat | Apache | 7.0.2 (including) | 7.0.2 (including) |
Tomcat | Apache | 7.0.3 (including) | 7.0.3 (including) |
Tomcat | Apache | 7.0.4 (including) | 7.0.4 (including) |
Tomcat | Apache | 7.0.5 (including) | 7.0.5 (including) |
Tomcat | Apache | 7.0.6 (including) | 7.0.6 (including) |
JBEWS 1.0 for RHEL 4 | RedHat | tomcat6-0:6.0.24-11.patch_03.ep5.el4 | * |
Red Hat Enterprise Linux 6 | RedHat | tomcat6-0:6.0.24-24.el6_0 | * |
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | RedHat | tomcat6-0:6.0.24-11.patch_03.ep5.el5 | * |
Red Hat JBoss Web Server 1.0 | RedHat | * | |
Tomcat6 | Ubuntu | karmic | * |
Tomcat6 | Ubuntu | lucid | * |
Tomcat6 | Ubuntu | maverick | * |