CVE-2012-4534: Low severity tomcat vulnerability
org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4534?
CVE-2012-4534 has been classified as a medium severity vulnerability due to the potential for denial of service.
How do I fix CVE-2012-4534?
To fix CVE-2012-4534, upgrade Apache Tomcat to version 6.0.36 or later for 6.x, and version 7.0.28 or later for 7.x.
What software is affected by CVE-2012-4534?
CVE-2012-4534 affects Apache Tomcat versions 6.0 to 6.0.35 and 7.0 to 7.0.27.
What attack vector is associated with CVE-2012-4534?
CVE-2012-4534 allows remote attackers to cause a denial of service by terminating the connection during the reading of a response.
Can CVE-2012-4534 be exploited remotely?
Yes, CVE-2012-4534 can be exploited remotely, allowing attackers to affect the service availability.