CVE-2014-0095
medium
CVSS v3
—
CVSS v2
5.0
VIR risk
5.0
Description
Denial of service in Apache Tomcat
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-8.html
Vendor advisory: secalert@redhat.com — http://svn.apache.org/viewvc?view=revision&revision=1578392
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat:tomcat-coyote | >=8.0.0-RC1,<8.0.4 | 8.0.4 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=8.0.0-RC1,<8.0.4 | 8.0.4 |
References
- http://seclists.org/fulldisclosure/2014/May/134
- http://secunia.com/advisories/59873
- http://secunia.com/advisories/60729
- http://svn.apache.org/viewvc?view=revision&revision=1578392
- http://tomcat.apache.org/security-8.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21678231
- http://www-01.ibm.com/support/docview.wss?uid=swg21681528
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.securityfocus.com/bid/67673
- http://www.securitytracker.com/id/1030300
- https://nvd.nist.gov/vuln/detail/CVE-2014-0095
- https://github.com/apache/tomcat/commit/8884dae60ace77a87ed9385442ce429e98c3a479
- https://github.com/apache/tomcat80/commit/77590c897f0e542fe363d70efdf3b82209510aee
- https://github.com/apache/tomcat
- https://web.archive.org/web/20140713043210/http://www.securitytracker.com/id/1030300
- https://web.archive.org/web/20141126170141/http://www.securityfocus.com/bid/67673
- https://web.archive.org/web/20151017043748/http://secunia.com/advisories/60729
- https://web.archive.org/web/20161024215453/http://secunia.com/advisories/59873
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.