ISOMAN

CVE

CVE-2016-3092

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://jvn.jp/en/jp/JVN89379547/index.html
  2. http://jvndb.jvn.jp/jvndb/JVNDB-2016-000121
  3. http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html
  4. http://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3E
  5. http://rhn.redhat.com/errata/RHSA-2016-2068.html
  6. http://rhn.redhat.com/errata/RHSA-2016-2069.html
  7. http://rhn.redhat.com/errata/RHSA-2016-2070.html
  8. http://rhn.redhat.com/errata/RHSA-2016-2071.html
  9. http://rhn.redhat.com/errata/RHSA-2016-2072.html
  10. http://rhn.redhat.com/errata/RHSA-2016-2599.html
  11. http://rhn.redhat.com/errata/RHSA-2016-2807.html
  12. http://rhn.redhat.com/errata/RHSA-2016-2808.html
  13. http://rhn.redhat.com/errata/RHSA-2017-0457.html
  14. http://svn.apache.org/viewvc?view=revision&revision=1743480
  15. http://svn.apache.org/viewvc?view=revision&revision=1743722
  16. http://svn.apache.org/viewvc?view=revision&revision=1743738
  17. http://svn.apache.org/viewvc?view=revision&revision=1743742
  18. http://tomcat.apache.org/security-7.html
  19. http://tomcat.apache.org/security-8.html
  20. http://tomcat.apache.org/security-9.html