Home
Ask the Team
Mailing Lists
Advertising Info
Advisories
About SecuriTeam
Blogs
Brought to you by:
Suppliers of:
New vulnerability? New tool? Tell us
Subjects of Interest:
Vulnerability Management
SQL Injection
Buffer Overflows
Active Network Scanning
Fuzzing
Fuzzer Report
Network Security
Network Scanner
Pen Testing
Security Scanner
Apache Tomcat is prone to a denial-of-service vulnerability.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/51200
The information has been provided by Alexander Klink, n.runs AG and Julian W Darmstadt .
Vulnerable Systems:
* Apache Software Foundation Tomcat 7.0.17
* Apache Software Foundation Tomcat 7.0.16
* Apache Software Foundation Tomcat 7.0.15
* Apache Software Foundation Tomcat 7.0.14
* Apache Software Foundation Tomcat 7.0.13
* Apache Software Foundation Tomcat 7.0.12
* Apache Software Foundation Tomcat 7.0.9
* Apache Software Foundation Tomcat 7.0.8
* Apache Software Foundation Tomcat 7.0.7
* Apache Software Foundation Tomcat 7.0.6
* Apache Software Foundation Tomcat 7.0.4
* Apache Software Foundation Tomcat 7.0.3
* Apache Software Foundation Tomcat 7.0.2
* Apache Software Foundation Tomcat 7.0.1
* Apache Software Foundation Tomcat 7.0 beta
* Apache Software Foundation Tomcat 7.0
* Apache Software Foundation Tomcat 6.0.32
* Apache Software Foundation Tomcat 6.0.29
* Apache Software Foundation Tomcat 6.0.28
* Apache Software Foundation Tomcat 6.0.28
* Apache Software Foundation Tomcat 6.0.27
* Apache Software Foundation Tomcat 6.0.27
* Apache Software Foundation Tomcat 6.0.26
* Apache Software Foundation Tomcat 6.0.25
* Apache Software Foundation Tomcat 6.0.24
* Apache Software Foundation Tomcat 6.0.20
* Apache Software Foundation Tomcat 6.0.18
* Apache Software Foundation Tomcat 6.0.17
* Apache Software Foundation Tomcat 6.0.16
* Apache Software Foundation Tomcat 6.0.15
* Apache Software Foundation Tomcat 6.0.14
* Apache Software Foundation Tomcat 6.0.13
* Apache Software Foundation Tomcat 6.0.12
* Apache Software Foundation Tomcat 6.0.11
* Apache Software Foundation Tomcat 6.0.10
* Apache Software Foundation Tomcat 6.0.9
* Apache Software Foundation Tomcat 6.0.8
* Apache Software Foundation Tomcat 6.0.7
* Apache Software Foundation Tomcat 6.0.6
* Apache Software Foundation Tomcat 6.0.5
* Apache Software Foundation Tomcat 6.0.4
* Apache Software Foundation Tomcat 6.0.3
* Apache Software Foundation Tomcat 6.0.2
* Apache Software Foundation Tomcat 6.0.1
* Apache Software Foundation Tomcat 6.0
* Apache Software Foundation Tomcat 5.5.34
* Apache Software Foundation Tomcat 5.5.32
* Apache Software Foundation Tomcat 5.5.30
* Apache Software Foundation Tomcat 5.5.30
* Apache Software Foundation Tomcat 5.5.29
* Apache Software Foundation Tomcat 5.5.28
* Apache Software Foundation Tomcat 5.5.27
* Apache Software Foundation Tomcat 5.5.26
* Apache Software Foundation Tomcat 5.5.25
* Apache Software Foundation Tomcat 5.5.24
* Apache Software Foundation Tomcat 5.5.23
* Apache Software Foundation Tomcat 5.5.22
* Apache Software Foundation Tomcat 5.5.21
* Apache Software Foundation Tomcat 5.5.20
* Apache Software Foundation Tomcat 5.5.19
* Apache Software Foundation Tomcat 5.5.18
* Apache Software Foundation Tomcat 5.5.17
* Apache Software Foundation Tomcat 5.5.16
* Apache Software Foundation Tomcat 5.5.15
* Apache Software Foundation Tomcat 5.5.14
* Apache Software Foundation Tomcat 5.5.13
* Apache Software Foundation Tomcat 5.5.12
* Apache Software Foundation Tomcat 5.5.11
* Apache Software Foundation Tomcat 5.5.10
* Apache Software Foundation Tomcat 5.5.9
* Apache Software Foundation Tomcat 5.5.8
* Apache Software Foundation Tomcat 5.5.7
* Apache Software Foundation Tomcat 5.5.6
* Apache Software Foundation Tomcat 5.5.5
* Apache Software Foundation Tomcat 5.5.4
* Apache Software Foundation Tomcat 5.5.3
* Apache Software Foundation Tomcat 5.5.2
* Apache Software Foundation Tomcat 5.5.1
* Apache Software Foundation Tomcat 5.5
* Apache Software Foundation Tomcat 5.4
* Apache Software Foundation Tomcat 5.3
* Apache Software Foundation Tomcat 5.2
* Apache Software Foundation Tomcat 5.1
* Apache Software Foundation Tomcat 5.0.31
* Apache Software Foundation Tomcat 5.0.30
* Apache Software Foundation Tomcat 5.0.28
* Apache Software Foundation Tomcat 5.0.19
* Apache Software Foundation Tomcat 5.0.16
* Apache Software Foundation Tomcat 5.0.15
* Apache Software Foundation Tomcat 5.0.14
* Apache Software Foundation Tomcat 5.0.13
* Apache Software Foundation Tomcat 5.0.12
* Apache Software Foundation Tomcat 5.0.11
* Apache Software Foundation Tomcat 5.0.10
* Apache Software Foundation Tomcat 5.0.9
* Apache Software Foundation Tomcat 5.0.8
* Apache Software Foundation Tomcat 5.0.7
* Apache Software Foundation Tomcat 5.0.6
* Apache Software Foundation Tomcat 5.0.5
* Apache Software Foundation Tomcat 5.0.4
* Apache Software Foundation Tomcat 5.0.3
* Apache Software Foundation Tomcat 5.0.2
* Apache Software Foundation Tomcat 5.0.1
* Apache Software Foundation Tomcat 5.0
* Apache Software Foundation Tomcat 7.0.5
* Apache Software Foundation Tomcat 7.0.22
* Apache Software Foundation Tomcat 7.0.21
* Apache Software Foundation Tomcat 7.0.20
* Apache Software Foundation Tomcat 7.0.19
* Apache Software Foundation Tomcat 7.0.18
* Apache Software Foundation Tomcat 7.0.11
* Apache Software Foundation Tomcat 7.0.10
* Apache Software Foundation Tomcat 7.0
* Apache Software Foundation Tomcat 6.0.33
* Apache Software Foundation Tomcat 6.0.32
* Apache Software Foundation Tomcat 6.0.31
* Apache Software Foundation Tomcat 6.0.30
* Apache Software Foundation Tomcat 6.0.29
* Apache Software Foundation Tomcat 6.0.19
* Apache Software Foundation Tomcat 5.5.33
* Apache Software Foundation Tomcat 5.5.31
* Apache Software Foundation Tomcat 5.0
* Apache Software Foundation Geronimo 2.1.7
* Apache Software Foundation Geronimo 2.1.6
* Apache Software Foundation Geronimo 2.1.5
* Apache Software Foundation Geronimo 2.1.4
* Apache Software Foundation Geronimo 2.1.3
* Apache Software Foundation Geronimo 2.1.2
* Apache Software Foundation Geronimo 2.1.1
* Apache Software Foundation Geronimo 2.0.2
* Apache Software Foundation Geronimo 2.0.1
* Apache Software Foundation Geronimo 1.1.1
* Apache Software Foundation Geronimo 1.1
* Apache Software Foundation Geronimo 1.0.1
* Apache Software Foundation Geronimo 1.0
* Apache Software Foundation Geronimo 2.1
* Apache Software Foundation Geronimo 2.0
* Apache Software Foundation Geronimo 1.2
* Apache Software Foundation Geronimo 1.1
* Apache Software Foundation Geronimo 1.0
Immune Systems:
* Apache Software Foundation Tomcat 7.0.23
* Apache Software Foundation Tomcat 6.0.35
* Apache Software Foundation Tomcat 5.5.35
* Apache Software Foundation Geronimo 2.1.8
An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.
Vendor Status:
Apache Software Foundation as issued an update for this vulnerablity.
Patch Availability:
http://httpd.apache.org/download.cgi
CVE Information:
CVE-2011-4858
Disclosure Timeline:
Intial release May 22 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by