Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 85383 - www-servers/tomcat: Apache Tomcat AJP12 Protocol Denial of Service Vulnerability
Summary: www-servers/tomcat: Apache Tomcat AJP12 Protocol Denial of Service Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/14569/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-15 11:41 UTC by Jean-François Brunette (RETIRED)
Modified: 2009-07-13 22:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-03-15 11:41:42 UTC
Description:
Hitachi Incident Response Team has reported a vulnerability in Tomcat, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the servlet / JSP communication handling for the AJP12 protocol. This can be exploited to cause a vulnerable server to stop processing further requests by sending a specially crafted request to the APJ12 protocol port (8007/tcp by default).

The vulnerability has been reported in version 3.x.

Solution:
The vulnerability has been fixed in the 5.x releases.

Filter traffic to the APJ12 protocol port (default is 8007/tcp).


Other References:
US-CERT VU#204710:
http://www.kb.cert.org/vuls/id/204710
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-03-15 13:00:01 UTC
Since 5.x versions are already in the tree, this just needs a GLSA decision.
Comment 2 Jan Brinkmann (RETIRED) gentoo-dev 2005-03-16 14:04:03 UTC
i think it's not a problem if version <5 are getting removed from the tree. i'll add an ebuild for 5.5.x in the near future as the 5.5 release is the latest stable release from upstream and the main focus of development. 
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-03-17 02:10:47 UTC
Voting half-yes...
Comment 4 Luke Macken (RETIRED) gentoo-dev 2005-03-17 16:42:10 UTC
I vote no.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-17 22:06:11 UTC

    
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-03-17 22:06:11 UTC
½ YES here too,
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-03-20 06:37:14 UTC
Reversing vote and voting no... AJP12 should always be filtered, and this has been fixed in 5.x since forever. Reopen if you intended to vote yes.