Bug 831119 (CVE-2012-3544) - VUL-0: CVE-2012-3544: tomcat6 tomcat7: Denial of service via chunked transfer encoding
Summary: VUL-0: CVE-2012-3544: tomcat6 tomcat7: Denial of service via chunked transfer...
Status: RESOLVED FIXED
Alias: CVE-2012-3544
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2013-08-09
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3:53858 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-24 12:34 UTC by Marcus Meissner
Modified: 2013-09-11 06:02 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-07-24 12:34:02 UTC
via tomcat advisory pages

CVE-2012-3544

 Important: Denial of service CVE-2012-3544

When processing a request submitted using the chunked transfer encoding, Tomcat ignored but did not limit any extensions that were included. This allows a client to perform a limited DOS by streaming an unlimited amount of data to the server.

TOMCAT6:
This was fixed in revision 1476592.

This issue was reported to the Tomcat security team on 10 November 2011 and made public on 10 May 2013.

Affects: 6.0.0-6.0.36

TOMCAT7:
This was fixed in revisions 1378702 and 1378921.

This issue was reported to the Tomcat security team on 10 November 2011 and made public on 10 May 2013.

Affects: 7.0.0-7.0.29
Comment 1 Marcus Meissner 2013-07-24 12:35:38 UTC
affects SLE11 tomcat6
Comment 2 Swamp Workflow Management 2013-07-24 22:00:34 UTC
bugbot adjusting priority
Comment 3 Michal Vyskocil 2013-07-26 13:10:31 UTC
fixed in bnc#822177
Comment 5 Bernhard Wiedemann 2013-07-26 14:00:34 UTC
This is an autogenerated message for OBS integration:
This bug (831119) was mentioned in
https://build.opensuse.org/request/show/184435 Maintenance /
Comment 6 Swamp Workflow Management 2013-07-26 15:20:38 UTC
The SWAMPID for this issue is 53781.
This issue was rated as moderate.
Please submit fixed packages until 2013-08-09.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 7 Bernhard Wiedemann 2013-07-30 14:00:39 UTC
This is an autogenerated message for OBS integration:
This bug (831119) was mentioned in
https://build.opensuse.org/request/show/184951 Maintenance /
Comment 10 Swamp Workflow Management 2013-08-07 08:05:33 UTC
openSUSE-SU-2013:1307-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 768772,804992,822177,831117,831119
CVE References: CVE-2013-1976,CVE-2013-2067,CVE-2013-3544
Sources used:
openSUSE 12.2 (src):    tomcat-7.0.27-2.19.1
Comment 11 Marcus Meissner 2013-08-07 19:04:35 UTC
We published this incorrectly with a 2013 CVE instead of a 2012 CVE. :(
Comment 12 Swamp Workflow Management 2013-08-22 22:15:20 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP2 (i386, x86_64)
Comment 13 Swamp Workflow Management 2013-08-22 22:20:27 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 14 Swamp Workflow Management 2013-08-22 22:46:07 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP1-TERADATA (x86_64)
SUSE-MANAGER 1.2 (x86_64)
Comment 15 Matthias Weckbecker 2013-08-27 10:15:36 UTC
released
Comment 16 Bernhard Wiedemann 2013-08-28 06:02:03 UTC
This is an autogenerated message for OBS integration:
This bug (831119) was mentioned in
https://build.opensuse.org/request/show/196597 Evergreen:11.2 / tomcat6
Comment 17 Swamp Workflow Management 2013-09-08 16:05:25 UTC
openSUSE-SU-2013:1411-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 768772,822177,831117,831119
CVE References: CVE-2012-3544,CVE-2013-1976,CVE-2013-2067
Sources used:
openSUSE 11.4 (src):    tomcat6-6.0.32-42.1
Comment 18 Bernhard Wiedemann 2013-09-11 06:02:51 UTC
This is an autogenerated message for OBS integration:
This bug (831119) was mentioned in
https://build.opensuse.org/request/show/198409 Evergreen:11.2 / tomcat6