Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
BID:56813
Info
Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
| Bugtraq ID: | 56813 |
| Class: | Design Error |
| CVE: |
CVE-2012-4534 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2012 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | Arun Neelicattu of the Red Hat Security Response Team |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 90.D3.06 Xerox FreeFlow Print Server (FFPS) 82.D2.24 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 82.C5.24 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 81.C3.31 Xerox FreeFlow Print Server (FFPS) 73.D4.31B Xerox FreeFlow Print Server (FFPS) 73.D4.31 Xerox FreeFlow Print Server (FFPS) 73.D2.33 VMWare vCenter Server 5.1 Redhat JBoss Enterprise Web Server EL6 2.0 Redhat JBoss Enterprise Web Server EL5 2.0 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 HP XP P9000 Performance Advisor 5.4.1 HP Service Manager 9.31 HP Service Manager 9.30 HP HP-UX B.11.31 Gentoo Linux CTERA Networks CTERA Portal 3.1 CentOS CentOS 6 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.17 Apache Tomcat 7.0.16 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 6.0.35 Apache Tomcat 6.0.32 Apache Tomcat 6.0.29 Apache Tomcat 6.0.28 Apache Tomcat 6.0.27 Apache Tomcat 6.0.26 Apache Tomcat 6.0.25 Apache Tomcat 6.0.24 Apache Tomcat 6.0.20 Apache Tomcat 6.0.18 Apache Tomcat 6.0.17 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 7.0.5 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.17 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 7.0 Apache Tomcat 6.0.33 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 Apache Tomcat 0 |
| Not Vulnerable: |
VMWare vCenter Server 5.1 Update 1 HP XP P9000 Performance Advisor 5.5.1 HP Service Manager 9.31.2004 p2 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Apache Tomcat 7.0.30 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 6.0.36 |
Discussion
Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
Apache Tomcat is prone to a denial-of-service vulnerability.
Attackers may leverage this issue to cause denial-of-service conditions.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.27
Tomcat 6.0.0 through 6.0.35
Apache Tomcat is prone to a denial-of-service vulnerability.
Attackers may leverage this issue to cause denial-of-service conditions.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.27
Tomcat 6.0.0 through 6.0.35
Exploit / POC
Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
An exploit is available. Please see the references for more information.
An exploit is available. Please see the references for more information.
Solution / Fix
Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Tomcat CVE-2012-4534 Denial of Service Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- CVE-2012-4534 Apache Tomcat denial of service (Mark Thomas)
- High CPU load in the NIO connector, when a client breaks connection unexpectedly (Dmitry Kukushkin)
- HPSBMU02873 SSRT101182 rev.1 - HP Service Manager, Apache Tomcat Security Update (HP)
- HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D (HP)
- Multiple Tomcat vulnerabilities in Oracle Health Sciences Clinical Development C (Oracle)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Xerox Security Bulletin XRX14-004 (Xerox)
- HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)
- Moderate: tomcat6 security update (Red Hat)
- VMware security updates for vCenter Server (VMware)