CVE-2014-0075

Description

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote attackers to cause a denial of service (resource consumption) via a malformed chunk size in chunked transfer coding of a request during the streaming of data.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
59.294

Associated Vulnerability

VulnerabilityOS Platform
Update Tomcat to 9.5.14Windows
Update Tomcat to 9.5.5Windows
Update Tomcat to 9.5.7Windows
Update Tomcat to 9.5.8Windows
Update Tomcat to 9.6.10Windows
Update Tomcat to 9.6.3Windows
Update Tomcat to 9.6.4Windows
Update Tomcat to 9.6.7Windows
Update Tomcat to 9.6.8Windows
Update Tomcat to 2.4.5Windows
Update Tomcat to 3.0.14Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.0Windows
Vulnerabilities CVE-2014-0075,CVE-2014-0099,CVE-2014-0096,CVE-2014-0119 are fixed in Apache - tomcat 6.0.40Windows
Vulnerabilities CVE-2014-0075 are fixed in Apache - tomcat 7.0.53Windows
Vulnerabilities CVE-2014-0075 are fixed in Apache - tomcat 8.0.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.9Windows
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate 6.0.40Windows
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate 7.0.53Windows
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate 8.0.4Windows
Tomcat7 7.0.52-1ubuntu0.11 for Ubuntu 14.04 LTS (x64) tomcat7_7.0.52-1ubuntu0.11_all.debLinux
Update Tomcat to 9.5.14 (For Linux)Linux
Update Tomcat to 9.5.5 (For Linux)Linux
Update Tomcat to 9.5.7 (For Linux)Linux
Update Tomcat to 9.5.8 (For Linux)Linux
Update Tomcat to 9.6.10 (For Linux)Linux
Update Tomcat to 9.6.3 (For Linux)Linux
Update Tomcat to 9.6.4 (For Linux)Linux
Update Tomcat to 9.6.7 (For Linux)Linux
Update Tomcat to 9.6.8 (For Linux)Linux
Update Tomcat to 2.4.5 (For Linux)Linux
Update Tomcat to 3.0.14 (For Linux)Linux
Vulnerabilities CVE-2014-0075,CVE-2014-0099,CVE-2014-0096,CVE-2014-0119 are fixed in Apache - tomcat for Linux 6.0.40Linux
Vulnerabilities CVE-2014-0075 are fixed in Apache - tomcat for Linux 7.0.53Linux
Vulnerabilities CVE-2014-0075 are fixed in Apache - tomcat for Linux 8.0.4Linux
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate for Linux 6.0.40Linux
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate for Linux 7.0.53Linux
Vulnerabilities CVE-2014-0075 are fixed in Apache-tomcat-coyate for Linux 8.0.4Linux
CVE-2014-0075NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234