(HP Issues Fix for HP-UX) Apache Tomcat Hash Table Collision Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1026642 |
|
SecurityTracker URL: http://securitytracker.com/id/1026642
|
|
CVE Reference:
CVE-2012-0022
(Links to External Site)
|
Date: Feb 6 2012
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): 5.5.34, 6.0.34, 7.0.22; and prior versions
|
Description:
A vulnerability was reported in Apache Tomcat. A remote user can cause denial of service conditions.
A remote user can send specially crafted POST request values to trigger hash collisions and cause significant performance degradation on the target server.
The original advisory is available at:
http://www.nruns.com/_downloads/advisory28122011.pdf
Alexander Klink of n.runs AG and Julian Walde of Technische Universitat Darmstadt reported this vulnerability. Scott A. Crosby and Dan S. Wallach of Rice University reported the theoretical attack.
|
Impact:
A remote user can cause performance to degrade on the target server.
|
Solution:
HP has issued a fix.
The HP advisory is available at:
http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03183543
|
Vendor URL: tomcat.apache.org/ (Links to External Site)
|
Cause:
Randomization error
|
Underlying OS:
UNIX (HP/UX)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Mon, 06 Feb 2012 23:45:33 +0000
Subject: HPSBUX02741 SSRT100728 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Access Restriction Bypass
|
CVE-2006-7243, CVE-2011-4858, CVE-2011-4885, CVE-2012-0022
h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03183543
|
|