oval:org.mitre.oval:def:24427
Definition Id: oval:org.mitre.oval:def:24427 | |||
Oval ID: | oval:org.mitre.oval:def:24427 | ||
Title: | RHSA-2014:0827: tomcat security update (Moderate) | ||
Description: | Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. It was discovered that Apache Tomcat did not limit the length of chunk sizes when using chunked transfer encoding. A remote attacker could use this flaw to perform a denial of service attack against Tomcat by streaming an unlimited quantity of data, leading to excessive consumption of server resources. (CVE-2014-0075) It was found that Apache Tomcat did not check for overflowing values when parsing request content length headers. A remote attacker could use this flaw to perform an HTTP request smuggling attack on a Tomcat server located behind a reverse proxy that processed the content length header correctly. (CVE-2014-0099) It was found that the org.apache.catalina.servlets.DefaultServlet implementation in Apache Tomcat allowed the definition of XML External Entities (XXEs) in provided XSLTs. A malicious application could use this to circumvent intended security restrictions to disclose sensitive information. (CVE-2014-0096) The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product Security. All Tomcat 7 users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. Tomcat must be restarted for this update to take effect. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:0827-00 CVE-2014-0075 CVE-2014-0096 CVE-2014-0099 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 7 CentOS Linux 7 | Product(s): | tomcat |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24953 | |||
Oval ID: | oval:org.mitre.oval:def:24953 | ||
Title: | The operating system installed on the system is Red Hat Enterprise Linux 7 | ||
Description: | The operating system installed on the system is Red Hat Enterprise Linux 7. | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:redhat:enterprise_linux:7 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 7 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:24427 |
Definition Id: oval:org.mitre.oval:def:24773 | |||
Oval ID: | oval:org.mitre.oval:def:24773 | ||
Title: | The operating system installed on the system is CentOS Linux 7.x | ||
Description: | The operating system installed on the system is CentOS Linux 7.x | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:centos:centos:7 | Version: | 3 |
Platform(s): | CentOS Linux 7 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:24427 |