CVE-2014-0050
Publication date 7 February 2014
Last updated 24 July 2024
Ubuntu priority
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Status
Package | Ubuntu Release | Status |
---|---|---|
libcommons-fileupload-java | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
tomcat6 | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
tomcat7 | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Notes
Patch details
Package | Patch details |
---|---|
libcommons-fileupload-java | |
tomcat7 |
References
Related Ubuntu Security Notices (USN)
- USN-2130-1
- Tomcat vulnerabilities
- 6 March 2014