{"id":"MGASA-2014-0148","summary":"Updated tomcat package fixes security vulnerabilities","details":"Apache Tomcat 7.x before 7.0.47, when an HTTP connector or AJP connector\nis used, does not properly handle certain inconsistent HTTP request\nheaders, which allows remote attackers to trigger incorrect identification\nof a request's length and conduct request-smuggling attacks via (1)\nmultiple Content-Length headers or (2) a Content-Length header and a\n\"Transfer-Encoding: chunked\" header (CVE-2013-4286).\n\nApache Tomcat 7.x before 7.0.50 processes chunked transfer coding without\nproperly handling (1) a large total amount of chunked data or (2)\nwhitespace characters in an HTTP header value within a trailer field,\nwhich allows remote attackers to cause a denial of service by streaming\ndata  (CVE-2013-4322).\n\nApache Tomcat 7.x before 7.0.50 allows attackers to obtain \"Tomcat\ninternals\" information by leveraging the presence of an untrusted web\napplication with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML\ndocument containing an external entity declaration in conjunction with an\nentity reference, related to an XML External Entity (XXE) issue\n(CVE-2013-4590).\n","modified":"2026-04-16T06:24:39.099499963Z","published":"2014-04-03T00:16:05Z","upstream":["CVE-2013-4286","CVE-2013-4322","CVE-2013-4590"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0148.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12955"},{"type":"WEB","url":"http://tomcat.apache.org/security-7.html"}],"affected":[{"package":{"name":"tomcat","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.52-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0148.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}