CVE-2011-0534: High severity tomcat vulnerability
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0534?
CVE-2011-0534 is considered to have a high severity due to the potential for denial of service attacks resulting in an OutOfMemoryError.
How do I fix CVE-2011-0534?
To fix CVE-2011-0534, upgrade to Apache Tomcat version 7.0.8 or later for Tomcat 7, or version 6.0.32 or later for Tomcat 6.
What versions of Apache Tomcat are affected by CVE-2011-0534?
CVE-2011-0534 affects Apache Tomcat versions 7.0.0 to 7.0.6 and 6.0.0 to 6.0.30.
What kind of attacks can exploit CVE-2011-0534?
CVE-2011-0534 can be exploited by remote attackers sending crafted HTTP requests, leading to a denial of service.
Is CVE-2011-0534 a local or remote vulnerability?
CVE-2011-0534 is a remote vulnerability, allowing attackers to exploit it without local access.