Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
BID:59797
Info
Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
| Bugtraq ID: | 59797 |
| Class: | Design Error |
| CVE: |
CVE-2012-3544 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2013 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | Steve Jones |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 90.D3.06 Xerox FreeFlow Print Server (FFPS) 82.D2.24 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 82.C5.24 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 81.C3.31 Xerox FreeFlow Print Server (FFPS) 73.D4.31B Xerox FreeFlow Print Server (FFPS) 73.D4.31 Xerox FreeFlow Print Server (FFPS) 73.D2.33 Ubuntu Ubuntu Linux 13.04 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS Redhat JBoss Enterprise Web Server 2.0.0 Oracle Virtual Desktop Infrastructure 3.3 Oracle Virtual Desktop Infrastructure 3.2 Oracle Transportation Management 6.3.2 Oracle Transportation Management 6.3.1 Oracle Transportation Management 6.3 Oracle Solaris 11.1 Oracle Secure Global Desktop 4.71 Oracle Secure Global Desktop 4.6 Oracle Oracle Transportation Management 6.2 Oracle Oracle Transportation Management 6.1 Oracle Oracle Transportation Management 6.0 Oracle Enterprise Data Quality 9.0.8 Oracle Enterprise Data Quality 8.1 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM WebSphere Application Server Community Edition 3.0.0.4 IBM WebSphere Application Server Community Edition 2.1.1.6 IBM Tivoli Application Dependency Discovery Manager 7.2.2 IBM Tivoli Application Dependency Discovery Manager 7.2.1 IBM Tivoli Application Dependency Discovery Manager 7.2.0 IBM Tivoli Application Dependency Discovery Manager 7.1.2 IBM Rational Lifecycle Adapter for HP ALM 1.1 IBM Rational Lifecycle Adapter for HP ALM 1.0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CTERA Networks CTERA Portal 3.1 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Messaging Application Server 5.2.1 Avaya Messaging Application Server 5.0.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5.0 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange 6.2 Avaya Meeting Exchange 6.0 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 Avaya IQ 4.1 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Server Edition 8.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya IP Office Application Server 5.0.1 Avaya IP Office Application Server 5.0 Avaya Aura Utility Services 6.2 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.3 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Platform 1.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.2 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Presence Services 5.2 Avaya Aura Presence Services 0 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing Standard Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Avaya Aura Application Server 5300 SIP Core 3.0 PB3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Avaya Aura Application Server 5300 SIP Core 2.0 PB26 Avaya Aura Application Server 5300 SIP Core 2.0 PB25 Avaya Aura Application Server 5300 SIP Core 2.0 PB23 Avaya Aura Application Server 5300 SIP Core 2.0 PB19 Avaya Aura Application Server 5300 SIP Core 2.0 PB16 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Server 5300 SIP Core 1.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.4 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.6 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 6.0 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 5.0 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.17 Apache Tomcat 7.0.16 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 6.0.36 Apache Tomcat 6.0.35 Apache Tomcat 6.0.29 Apache Tomcat 6.0.28 Apache Tomcat 6.0.27 Apache Tomcat 6.0.26 Apache Tomcat 6.0.25 Apache Tomcat 6.0.24 Apache Tomcat 6.0.20 Apache Tomcat 6.0.18 Apache Tomcat 6.0.17 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 7.0.5 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.17 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 7.0 Apache Tomcat 6.0.33 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 |
| Not Vulnerable: |
Redhat JBoss Enterprise Web Server 2.0.1 Oracle Solaris 11.1.11.4.0 IBM Tivoli Application Dependency Discovery Manager 7.2.2.1 IBM Tivoli Application Dependency Discovery Manager 7.2.1.6 IBM Tivoli Application Dependency Discovery Manager 7.2.0.10 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Apache Tomcat 7.0.30 Apache Tomcat 6.0.37 |
Discussion
Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
Apache Tomcat is prone to a denial-of-service vulnerability.
Attackers may leverage this issue to cause denial-of-service conditions.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.29
Tomcat 6.0.0 through 6.0.36
Apache Tomcat is prone to a denial-of-service vulnerability.
Attackers may leverage this issue to cause denial-of-service conditions.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.29
Tomcat 6.0.0 through 6.0.36
Exploit / POC
Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Tomcat CVE-2012-3544 Denial of Service Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- CVE-2012-3544 Chunked transfer encoding extension size is not limited (Steve Jones)
- CVE-2012-3544 Fixed in Apache Tomcat 7.0.30 (Apache)
- CVE-2012-3544: Fixed in Apache Tomcat 6.0.37 (Apache Software Foundation)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Multiple vulnerabilities in Tomcat (Oracle)
- Rational Lifecycle Adapter for HP ALM Apache Tomcat fix (IBM)
- Xerox Security Bulletin XRX14-004 (Xerox)
- Apache Tomcat Chunked transfer encoding extension size is not limited (CVE-2012- (Avaya)
- Oracle Critical Patch Update Advisory - January 2014 (Oracle)
- Oracle Critical Patch Update Advisory - July 2014 (Oracle)
- Security vulnerabilities in Apache Tomcat for WebSphere Application Server (IBM)
- Tivoli Application Dependency Discovery Manager - Open Source Tomcat issues (IBM)