{"schema_version":"1.7.3","id":"GHSA-xx68-jfcg-xmmf","published":"2018-12-21T17:51:42Z","modified":"2024-12-02T05:45:08.176178Z","aliases":["CVE-2014-0050"],"summary":"Commons FileUpload Denial of service vulnerability","details":"MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.","affected":[{"package":{"name":"commons-fileupload:commons-fileupload","ecosystem":"Maven","purl":"pkg:maven/commons-fileupload/commons-fileupload"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1"}]}],"versions":["1.0","1.0-beta-1","1.0-rc1","1.1","1.1.1","1.2","1.2.1","1.2.2","1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-RC1"},{"fixed":"8.0.3"}]}],"versions":["8.0.0-RC1","8.0.0-RC10","8.0.0-RC3","8.0.0-RC5","8.0.1"],"database_specific":{"last_known_affected_version_range":"<= 8.0.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.52"}]}],"versions":["7.0.35","7.0.37","7.0.39","7.0.40","7.0.41","7.0.42","7.0.47","7.0.50"],"database_specific":{"last_known_affected_version_range":"<= 7.0.50","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-xx68-jfcg-xmmf/GHSA-xx68-jfcg-xmmf.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0050"},{"type":"WEB","url":"https://github.com/apache/commons-fileupload/commit/c61ff05b3241cb14d989b67209e57aa71540417a"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/29384723d8d9645b87e05be9fa369a4deeb78b9c"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1062337"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xx68-jfcg-xmmf"},{"type":"PACKAGE","url":"https://github.com/apache/commons-fileupload"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917"},{"type":"WEB","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722"},{"type":"WEB","url":"https://svn.apache.org/viewvc?view=revision&revision=1565143"},{"type":"WEB","url":"https://svn.apache.org/viewvc?view=revision&revision=1565163"},{"type":"WEB","url":"https://svn.apache.org/viewvc?view=revision&revision=1565169"},{"type":"WEB","url":"https://tomcat.apache.org/security-7.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"http://advisories.mageia.org/MGASA-2014-0110.html"},{"type":"WEB","url":"http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops-without-boundaries.html"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN14876762/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000017"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907@apache.org%3E"},{"type":"WEB","url":"http://marc.info/?l=bugtraq&m=143136844732487&w=2"},{"type":"WEB","url":"http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0252.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0253.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0400.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"type":"WEB","url":"http://secunia.com/advisories/57915"},{"type":"WEB","url":"http://secunia.com/advisories/58075"},{"type":"WEB","url":"http://secunia.com/advisories/58976"},{"type":"WEB","url":"http://secunia.com/advisories/59039"},{"type":"WEB","url":"http://secunia.com/advisories/59041"},{"type":"WEB","url":"http://secunia.com/advisories/59183"},{"type":"WEB","url":"http://secunia.com/advisories/59184"},{"type":"WEB","url":"http://secunia.com/advisories/59185"},{"type":"WEB","url":"http://secunia.com/advisories/59187"},{"type":"WEB","url":"http://secunia.com/advisories/59232"},{"type":"WEB","url":"http://secunia.com/advisories/59399"},{"type":"WEB","url":"http://secunia.com/advisories/59492"},{"type":"WEB","url":"http://secunia.com/advisories/59500"},{"type":"WEB","url":"http://secunia.com/advisories/59725"},{"type":"WEB","url":"http://secunia.com/advisories/60475"},{"type":"WEB","url":"http://secunia.com/advisories/60753"},{"type":"WEB","url":"http://svn.apache.org/r1565143"},{"type":"WEB","url":"http://tomcat.apache.org/security-7.html"},{"type":"WEB","url":"http://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21669554"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21675432"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676091"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676092"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676401"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676403"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676405"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676410"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676656"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21676853"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21677691"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21677724"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21681214"},{"type":"WEB","url":"http://www.debian.org/security/2014/dsa-2856"},{"type":"WEB","url":"http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-015/index.html"},{"type":"WEB","url":"http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-016/index.html"},{"type":"WEB","url":"http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-017/index.html"},{"type":"WEB","url":"http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm"},{"type":"WEB","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:084"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/532549/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/65400"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2130-1"},{"type":"WEB","url":"http://www.vmware.com/security/advisories/VMSA-2014-0007.html"},{"type":"WEB","url":"http://www.vmware.com/security/advisories/VMSA-2014-0008.html"},{"type":"WEB","url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html"}],"database_specific":{"cwe_ids":["CWE-20"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:04:56Z","nvd_published_at":"2014-04-01T06:27:00Z","severity":"HIGH"}}