MGASA-2014-0148

Source
https://advisories.mageia.org/MGASA-2014-0148.html
Import Source
https://advisories.mageia.org/MGASA-2014-0148.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0148
Upstream
  • CVE-2013-4286
  • CVE-2013-4322
  • CVE-2013-4590
Published
2014-04-03T00:16:05Z
Modified
2026-04-16T06:24:39Z
Summary
Updated tomcat package fixes security vulnerabilities
Details

Apache Tomcat 7.x before 7.0.47, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header (CVE-2013-4286).

Apache Tomcat 7.x before 7.0.50 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data (CVE-2013-4322).

Apache Tomcat 7.x before 7.0.50 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue (CVE-2013-4590).

References
Credits

Affected packages

Mageia:3 / tomcat

Package

Name
tomcat
Purl
pkg:rpm/mageia/tomcat?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.0.52-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0148.json"