tomcat: Limited DoS in chunked transfer encoding input filter
Published Jun 1, 2013
5.0
MEDIUMCVSS 2.0
EPSS 11.00%
Description
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
Affected products
No data.
Configuration 1
- 6.0
- 6.0.0
- 6.0.0
- 6.0.1
- 6.0.1
- 6.0.2
- 6.0.2
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.4
- 6.0.5
- 6.0.6
- 6.0.6
- 6.0.7
- 6.0.7
- 6.0.7
- 6.0.8
- 6.0.8
- 6.0.9
- 6.0.9
- 6.0.10
- 6.0.11
- 6.0.12
- 6.0.13
- 6.0.14
- 6.0.15
- 6.0.16
- 6.0.17
- 6.0.18
- 6.0.19
- 6.0.20
- 6.0.24
- 6.0.26
- 6.0.27
- 6.0.28
- 6.0.29
- 6.0.30
- 6.0.31
- 6.0.32
- 6.0.33
- 6.0.35
- 6.0.36
Configuration 2
- 7.0.0
- 7.0.0
- 7.0.1
- 7.0.2
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.0.10
- 7.0.11
- 7.0.12
- 7.0.13
- 7.0.14
- 7.0.15
- 7.0.16
- 7.0.17
- 7.0.18
- 7.0.19
- 7.0.20
- 7.0.21
- 7.0.22
- 7.0.23
- 7.0.25
- 7.0.28
No data.
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
apache-commons-daemon-eap6-1:1.0.15-4.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
apache-commons-daemon-jsvc-eap6-1:1.0.15-1.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
apache-commons-pool-eap6-0:1.6-6.redhat_4.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
dom4j-0:1.6.1-19.redhat_5.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
ecj3-1:3.7.2-6.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
httpd-0:2.2.22-23.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
mod_cluster-0:1.2.4-1.Final_redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
mod_cluster-native-0:1.2.4-1.Final.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
mod_jk-0:1.2.37-2.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
tomcat-native-0:1.1.27-4.redhat_1.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
tomcat6-0:6.0.37-8_patch_01.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
tomcat7-0:7.0.40-9_patch_01.ep6.el5
Fixed · RHSA-2013:1011
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
apache-commons-daemon-eap6-1:1.0.15-4.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
apache-commons-daemon-jsvc-eap6-1:1.0.15-1.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
apache-commons-pool-eap6-0:1.6-6.redhat_4.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
dom4j-0:1.6.1-19.redhat_5.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
ecj3-1:3.7.2-6.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
httpd-0:2.2.22-23.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
mod_cluster-0:1.2.4-1.Final_redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
mod_cluster-native-0:1.2.4-1.Final.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
mod_jk-0:1.2.37-2.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat-native-0:1.1.27-4.redhat_1.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat6-0:6.0.37-10_patch_01.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat7-0:7.0.40-5_patch_01.ep6.el6
Fixed · RHSA-2013:1012
Red Hat JBoss Web Server 2.0
n/a
Fixed · RHSA-2013:1013
Red Hat Enterprise Linux 5
tomcat5
Not affected
Red Hat Enterprise Linux 6
tomcat6
Not affected
Red Hat JBoss Enterprise Application Platform 6
jbossweb
Not affected
Red Hat JBoss Enterprise Web Server 1
tomcat5
Not affected
Red Hat JBoss Enterprise Web Server 1
tomcat6
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | apache-commons-daemon-eap6-1:1.0.15-4.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | apache-commons-daemon-jsvc-eap6-1:1.0.15-1.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | apache-commons-pool-eap6-0:1.6-6.redhat_4.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | dom4j-0:1.6.1-19.redhat_5.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | ecj3-1:3.7.2-6.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | httpd-0:2.2.22-23.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | mod_cluster-0:1.2.4-1.Final_redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | mod_cluster-native-0:1.2.4-1.Final.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | mod_jk-0:1.2.37-2.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat-native-0:1.1.27-4.redhat_1.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat6-0:6.0.37-8_patch_01.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat7-0:7.0.40-9_patch_01.ep6.el5 | Fixed | RHSA-2013:1011 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | apache-commons-daemon-eap6-1:1.0.15-4.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | apache-commons-daemon-jsvc-eap6-1:1.0.15-1.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | apache-commons-pool-eap6-0:1.6-6.redhat_4.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | dom4j-0:1.6.1-19.redhat_5.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | ecj3-1:3.7.2-6.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | httpd-0:2.2.22-23.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | mod_cluster-0:1.2.4-1.Final_redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | mod_cluster-native-0:1.2.4-1.Final.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | mod_jk-0:1.2.37-2.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat-native-0:1.1.27-4.redhat_1.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat6-0:6.0.37-10_patch_01.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat7-0:7.0.40-5_patch_01.ep6.el6 | Fixed | RHSA-2013:1012 |
| Red Hat JBoss Web Server 2.0 | n/a | Fixed | RHSA-2013:1013 |
| Red Hat Enterprise Linux 5 | tomcat5 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | tomcat6 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | tomcat5 | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | tomcat6 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects Apache Tomcat 6.0.30 - 6.0.36 and 7.0.0 - 7.0.29. It does not affect JBoss Web.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 11.00% (0.11001) | 95.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 10.80% (0.10798) | 95.26th | v5 (v2026.06.15) |
| Jun 8, 2026 | 38.14% (0.38137) | 97.31th | v4 (v2025.03.14) |
| Dec 16, 2025 | 44.48% (0.44479) | 97.42th | v4 (v2025.03.14) |
| Dec 10, 2025 | 51.02% (0.51015) | 97.74th | v4 (v2025.03.14) |
| Sep 26, 2025 | 44.48% (0.44479) | 97.49th | v4 (v2025.03.14) |
| Jun 19, 2025 | 38.14% (0.38137) | 97.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 44.48% (0.44479) | 97.26th | v4 (v2025.03.14) |
| Feb 28, 2025 | 6.12% (0.06117) | 93.59th | v3 (v2023.03.01) |
| Dec 17, 2024 | 8.41% (0.08407) | 94.40th | v3 (v2023.03.01) |
| Jun 25, 2024 | 71.75% (0.71750) | 98.09th | v3 (v2023.03.01) |
| Dec 18, 2023 | 92.29% (0.92288) | 98.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 93.40% (0.93397) | 98.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (32)
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0042.html mailing-listx_refsource_BUGTRAQ
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listx_refsource_FULLDISC
- http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/coyote/http11/filters/ChunkedInputFilter.java?r1=1476592&r2=1476591&pathrev=1476592 x_refsource_CONFIRMPatch
- http://svn.apache.org/viewvc?view=revision&revision=1378702 x_refsource_CONFIRMPatch
- http://svn.apache.org/viewvc?view=revision&revision=1378921 x_refsource_CONFIRMPatch
- http://svn.apache.org/viewvc?view=revision&revision=1476592 x_refsource_CONFIRMPatch
- http://tomcat.apache.org/security-6.html x_refsource_CONFIRMVendor Advisory
- http://tomcat.apache.org/security-7.html x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/59797 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/64758 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1841-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2012-3544 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=961783 Issue Tracking
- https://github.com/advisories/GHSA-qfxv-3ppc-7qg5 Advisory
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2012-3544
- https://www.cve.org/CVERecord?id=CVE-2012-3544
Change history (0)
No recorded changes yet.