The Apache Tomcat developers are advising users of the 7.0.x, 6.0.x and 5.5.x branches of the Java servlet and JSP container to update to the latest released versions 7.0.23, 6.0.35 and 5.5.35. Recent investigations revealed inefficiencies in how large numbers of parameters and parameter values were handled by Tomcat.
Analysis of the recent hash collision denial-of-service (DoS) vulnerability had allowed the developers to identify “unrelated inefficiencies” which could be exploited by a specially crafted request, causing large amounts of CPU to be consumed. To address the issue, the developers modified the code to efficiently process large numbers of parameters and values.
Read this full article at H Security
Only registered users can write comments.
Please login or register.
Powered by AkoComment!
Article source: http://www.linuxsecurity.com/content/view/156591?rdf
Categories
Ads
Archives
Posts
- The Midweek Download: Feb. 22nd Edition–Three from Building Windows 8, the Windows Logo Re-Designed, plus Windows Phone, Dynamics CRM & Internet Explorer
- Google also bypassed cookie settings in Internet Explorer
- Google says IE privacy policy is impractical in modern Web
- Scared of Anonymous? NSA chief says you should be
- Hackers Were Scary in 1990
Comments
- Outsourcing tasks to online services » HowtoBecomeRichQuick.com on Hackers could have TAKEN OVER Amazon Web Services
- Virtualization is not evil. It’s sarcastic. | Twiddle Geek on Kernel Developers Share Security Tips
- Eliza on Fact or fiction? Hacker hit men can remotely murder through programmable insulin pumps
- neil martin on Suspected Hacker Highlights Computer Security Issues
- Radu on How to Build a Distributed Monitoring Solution with Nagios






