An Apache Tomcat Denial of Service vulnerability has been identified in apache Tomcat versions
6.0.0 through 6.0.35 and 7.0.0 through 7.0.27
The vulnerability is decribed as:
"The checks that limited the permitted size of request headers were implemented too late in the request parsing process for the HTTP NIO connector. This enabled a malicious user to trigger an OutOfMemoryError by sending a single request with very large headers."
Users are advised to upgrade to Apache Tomcat version 6.0.36 (or later) or 7.0.28 (or later).
6.0.0 through 6.0.35 and 7.0.0 through 7.0.27
The vulnerability is decribed as:
"The checks that limited the permitted size of request headers were implemented too late in the request parsing process for the HTTP NIO connector. This enabled a malicious user to trigger an OutOfMemoryError by sending a single request with very large headers."
Users are advised to upgrade to Apache Tomcat version 6.0.36 (or later) or 7.0.28 (or later).
Comments
Post a Comment