Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
BID:15325
Info
Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
| Bugtraq ID: | 15325 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-3510 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2005 12:00AM |
| Updated: | Aug 05 2010 08:45PM |
| Credit: | David Maciejak <[email protected]> discovered this issue. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9_sparc Sun Solaris 10_x86 Sun Solaris 10_sparc Redhat Red Hat Network Satellite Server 5.0 Redhat Red Hat Network Satellite Server 4.2 Redhat Red Hat Network Satellite Server 4.1 Redhat Red Hat Network Satellite Server 4.0 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Certificate Server 7.3 Computer Associates Cohesion Application Configuration Manager 4.5 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.10 Apache Tomcat 5.5.9 Apache Tomcat 5.5.8 Apache Tomcat 5.5.7 Apache Tomcat 5.5.6 Apache Tomcat 5.5.5 Apache Tomcat 5.5.4 Apache Tomcat 5.5.3 Apache Tomcat 5.5.2 Apache Tomcat 5.5.1 Apache Tomcat 5.5 |
| Not Vulnerable: |
Computer Associates Cohesion Application Configuration Manager 4.5 SP1 Apache Tomcat 5.5.12 Apache Tomcat 5.0.28 |
Discussion
Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
A remote denial-of-service vulnerability affects Apache Tomcat because the application fails to efficiently handle multiple requests for directory listings.
When this issue is triggered, the application fails to serve further requests to legitimate users until the Tomcat processes have been restarted.
A remote denial-of-service vulnerability affects Apache Tomcat because the application fails to efficiently handle multiple requests for directory listings.
When this issue is triggered, the application fails to serve further requests to legitimate users until the Tomcat processes have been restarted.
Exploit / POC
Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
Solution:
Updates are available. Please see the references for more information.
Sun Solaris 9_x86
References
Apache Tomcat Simultaneous Directory Listing Denial Of Service Vulnerability
References:
References:
- Tomcat Homepage (Apache Software Foundation)
- Apache Tomcat 5.5.x remote Denial Of Service (David Maciejak
) - CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1) ("Williams, James K"
) - CA20090123-01: Security Notice for Cohesion Tomcat (Computer Associates)
- RHSA-2007:1069-5 Moderate: tomcat security update for Red Hat Network Satellite (Red Hat)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)
- Security Vulnerabilities in Tomcat 4.0 Shipped with Solaris 9 and 10 (Sun Microsystems)