Oval Definition:oval:com.redhat.rhsa:def:20140827
Revision Date:2014-07-02Version:639
Title:RHSA-2014:0827: tomcat security update (Moderate)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

  • It was discovered that Apache Tomcat did not limit the length of chunk sizes when using chunked transfer encoding. A remote attacker could use this flaw to perform a denial of service attack against Tomcat by streaming an unlimited quantity of data, leading to excessive consumption of server resources. (CVE-2014-0075)

  • It was found that Apache Tomcat did not check for overflowing values when parsing request content length headers. A remote attacker could use this flaw to perform an HTTP request smuggling attack on a Tomcat server located behind a reverse proxy that processed the content length header correctly. (CVE-2014-0099)

  • It was found that the org.apache.catalina.servlets.DefaultServlet implementation in Apache Tomcat allowed the definition of XML External Entities (XXEs) in provided XSLTs. A malicious application could use this to circumvent intended security restrictions to disclose sensitive information. (CVE-2014-0096)

    The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product Security.

    All Tomcat 7 users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. Tomcat must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-0075
    CVE-2014-0075
    CVE-2014-0096
    CVE-2014-0096
    CVE-2014-0099
    CVE-2014-0099
    RHSA-2014:0827
    RHSA-2014:0827-00
    RHSA-2014:0827-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • tomcat is earlier than 0:7.0.42-6.el7_0
  • AND tomcat is signed with Red Hat redhatrelease2 key
  • tomcat-admin-webapps is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-admin-webapps is signed with Red Hat redhatrelease2 key
  • tomcat-docs-webapp is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-docs-webapp is signed with Red Hat redhatrelease2 key
  • tomcat-el-2.2-api is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-el-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-javadoc is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat-jsp-2.2-api is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-jsp-2.2-api is signed with Red Hat redhatrelease2 key
  • tomcat-jsvc is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-jsvc is signed with Red Hat redhatrelease2 key
  • tomcat-lib is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-lib is signed with Red Hat redhatrelease2 key
  • tomcat-servlet-3.0-api is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-servlet-3.0-api is signed with Red Hat redhatrelease2 key
  • tomcat-webapps is earlier than 0:7.0.42-6.el7_0
  • AND tomcat-webapps is signed with Red Hat redhatrelease2 key
  • BACK