MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
|
|
Oracle
Subscribe
|
Retail Applications
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Jboss Operations Network
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2856-1 | libcommons-fileupload-java security update |
Debian DSA |
DSA-2897-1 | tomcat7 security update |
Github GHSA |
GHSA-xx68-jfcg-xmmf | Commons FileUpload Denial of service vulnerability |
Ubuntu USN |
USN-2130-1 | Tomcat vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.958Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0050
No data.
Status : Deferred
Published: 2014-04-01T06:27:51.373
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0050
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA
Ubuntu USN