CVE-2012-2733
Publication date 16 November 2012
Last updated 24 July 2024
Ubuntu priority
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat6 | ||
tomcat7 | ||
Patch details
Package | Patch details |
---|---|
tomcat6 | |
tomcat7 |
References
Related Ubuntu Security Notices (USN)
- USN-1637-1
- Tomcat vulnerabilities
- 21 November 2012