CVE
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
◆ Tomcat
◆ Tomcat
◆ Earlier versions are not affected
Description:
For performance reasons
cached in two places: the internal request object and the internal
processor object
When certain errors occur that needed to be added to the access log
access logging process triggers the re
after it has been recycled
before being used for the next request
(e
next request
The issue was resolved be ensuring that the request and response objects
were recycled after being re
log entries
解決的辦法
◆ Tomcat
◆ Tomcat
CVE
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
◆ Tomcat
◆ Tomcat
◆ Tomcat
◆ Earlier
Description:
Analysis of the recent hash collision vulnerability identified unrelated
inefficiencies with Apache Tomcat
parameters and parameter values
attacker
to be used which in turn could create a denial of service
The issue was addressed by modifying the Tomcat parameter handling code
to efficiently process large numbers of parameters and parameter values
Mitigation:
Users of affected versions should apply one of the following mitigations:
◆ Tomcat
◆ Tomcat
◆ Tomcat
From:http://tw.wingwit.com/Article/program/Java/ky/201311/28189.html