CVE-2013-4322: Input Validation

Published Feb 25, 2014
·
Updated

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544.

Other sources

The fix for CVE-2012-3544 was not complete. It did not cover the following cases:

a) Chunk extensions were not limited b) Whitespace after the : in a trailing header was not limited

This has been corrected in upstream versions 8.0.0-rc10 [1],[2], 7.0.50 [3],[4], and 6.0.39 [5]

[1] http://svn.apache.org/viewvc?view=revision&revision=1521834 [2] http://svn.apache.org/viewvc?view=revision&revision=1549522 [3] http://svn.apache.org/viewvc?view=revision&revision=1521864 [4] http://svn.apache.org/viewvc?view=revision&revision=1549523 [5] http://svn.apache.org/viewvc?view=revision&revision=1556540

This could lead to a remote attacker causing a denial of service by streaming data, because Tomcat did not fully handle chunk extensions in chunked transfer coding.

Red Hat

Affected Software

197 affected componentsFixes available
maven/org.apache.tomcat:tomcat>=7.0.0<7.0.50
7.0.50
maven/org.apache.tomcat:tomcat>=8.0.0-RC1<8.0.0-RC10
8.0.0-RC10
maven/org.apache.tomcat:tomcat<6.0.39
6.0.39
redhat/tomcat<7.0.50
7.0.50
redhat/tomcat<6.0.39
6.0.39
redhat/tomcat<8.0.0
8.0.0
Apache Tomcat=7.0.0
Apache Tomcat=7.0.0-beta
Apache Tomcat=7.0.1
Apache Tomcat=7.0.2
Apache Tomcat=7.0.2-beta
Apache Tomcat=7.0.3
Apache Tomcat=7.0.4
Apache Tomcat=7.0.4-beta
Apache Tomcat=7.0.10
Apache Tomcat=7.0.11
Apache Tomcat=7.0.12
Apache Tomcat=7.0.13
Apache Tomcat=7.0.14
Apache Tomcat=7.0.15
Apache Tomcat=7.0.16
Apache Tomcat=7.0.17
Apache Tomcat=7.0.18
Apache Tomcat=7.0.19
Apache Tomcat=7.0.20
Apache Tomcat=7.0.21
Apache Tomcat=7.0.22
Apache Tomcat=7.0.23
Apache Tomcat=7.0.24
Apache Tomcat=7.0.25
Apache Tomcat=7.0.26
Apache Tomcat=7.0.27
Apache Tomcat=7.0.28
Apache Tomcat=7.0.29
Apache Tomcat=7.0.30
Apache Tomcat=7.0.31
Apache Tomcat=7.0.32
Apache Tomcat=7.0.33
Apache Tomcat=7.0.34
Apache Tomcat=7.0.35
Apache Tomcat=7.0.36
Apache Tomcat=7.0.37
Apache Tomcat=7.0.38
Apache Tomcat=7.0.39
Apache Tomcat=7.0.40
Apache Tomcat=7.0.41
Apache Tomcat=7.0.42
Apache Tomcat=7.0.43
Apache Tomcat=7.0.44
Apache Tomcat=7.0.45
Apache Tomcat=7.0.46
Apache Tomcat=7.0.50
Apache Tomcat<=6.0.37
Apache Tomcat=1.1.3
Apache Tomcat=3.0
Apache Tomcat=3.1
Apache Tomcat=3.1.1
Apache Tomcat=3.2
Apache Tomcat=3.2.1
Apache Tomcat=3.2.2
Apache Tomcat=3.2.2-beta2
Apache Tomcat=3.2.3
Apache Tomcat=3.2.4
Apache Tomcat=3.3
Apache Tomcat=3.3.1
Apache Tomcat=3.3.1a
Apache Tomcat=3.3.2
Apache Tomcat=4
Apache Tomcat=4.0.0
Apache Tomcat=4.0.1
Apache Tomcat=4.0.2
Apache Tomcat=4.0.3
Apache Tomcat=4.0.4
Apache Tomcat=4.0.5
Apache Tomcat=4.0.6
Apache Tomcat=4.1.0
Apache Tomcat=4.1.1
Apache Tomcat=4.1.2
Apache Tomcat=4.1.3
Apache Tomcat=4.1.3-beta
Apache Tomcat=4.1.9-beta
Apache Tomcat=4.1.10
Apache Tomcat=4.1.12
Apache Tomcat=4.1.15
Apache Tomcat=4.1.24
Apache Tomcat=4.1.28
Apache Tomcat=4.1.29
Apache Tomcat=4.1.31
Apache Tomcat=4.1.36
Apache Tomcat=5
Apache Tomcat=5.0.0
Apache Tomcat=5.0.1
Apache Tomcat=5.0.2
Apache Tomcat=5.0.3
Apache Tomcat=5.0.4
Apache Tomcat=5.0.5
Apache Tomcat=5.0.6
Apache Tomcat=5.0.7
Apache Tomcat=5.0.8
Apache Tomcat=5.0.9
Apache Tomcat=5.0.10
Apache Tomcat=5.0.11
Apache Tomcat=5.0.12
Apache Tomcat=5.0.13
Apache Tomcat=5.0.14
Apache Tomcat=5.0.15
Apache Tomcat=5.0.16
Apache Tomcat=5.0.17
Apache Tomcat=5.0.18
Apache Tomcat=5.0.19
Apache Tomcat=5.0.21
Apache Tomcat=5.0.22
Apache Tomcat=5.0.23
Apache Tomcat=5.0.24
Apache Tomcat=5.0.25
Apache Tomcat=5.0.26
Apache Tomcat=5.0.27
Apache Tomcat=5.0.28
Apache Tomcat=5.0.29
Apache Tomcat=5.0.30
Apache Tomcat=5.5.0
Apache Tomcat=5.5.1
Apache Tomcat=5.5.2
Apache Tomcat=5.5.3
Apache Tomcat=5.5.4
Apache Tomcat=5.5.5
Apache Tomcat=5.5.6
Apache Tomcat=5.5.7
Apache Tomcat=5.5.8
Apache Tomcat=5.5.9
Apache Tomcat=5.5.10
Apache Tomcat=5.5.11
Apache Tomcat=5.5.12
Apache Tomcat=5.5.13
Apache Tomcat=5.5.14
Apache Tomcat=5.5.15
Apache Tomcat=5.5.16
Apache Tomcat=5.5.17
Apache Tomcat=5.5.18
Apache Tomcat=5.5.19
Apache Tomcat=5.5.20
Apache Tomcat=5.5.21
Apache Tomcat=5.5.22
Apache Tomcat=5.5.23
Apache Tomcat=5.5.24
Apache Tomcat=5.5.25
Apache Tomcat=5.5.26
Apache Tomcat=5.5.27
Apache Tomcat=5.5.28
Apache Tomcat=5.5.29
Apache Tomcat=5.5.30
Apache Tomcat=5.5.31
Apache Tomcat=5.5.32
Apache Tomcat=5.5.33
Apache Tomcat=5.5.34
Apache Tomcat=5.5.35
Apache Tomcat=6
Apache Tomcat=6.0
Apache Tomcat=6.0.0
Apache Tomcat=6.0.0-alpha
Apache Tomcat=6.0.1
Apache Tomcat=6.0.1-alpha
Apache Tomcat=6.0.2
Apache Tomcat=6.0.2-alpha
Apache Tomcat=6.0.2-beta
Apache Tomcat=6.0.3
Apache Tomcat=6.0.10
Apache Tomcat=6.0.11
Apache Tomcat=6.0.12
Apache Tomcat=6.0.13
Apache Tomcat=6.0.14
Apache Tomcat=6.0.15
Apache Tomcat=6.0.16
Apache Tomcat=6.0.17
Apache Tomcat=6.0.18
Apache Tomcat=6.0.19
Apache Tomcat=6.0.20
Apache Tomcat=6.0.24
Apache Tomcat=6.0.26
Apache Tomcat=6.0.27
Apache Tomcat=6.0.28
Apache Tomcat=6.0.29
Apache Tomcat=6.0.30
Apache Tomcat=6.0.31
Apache Tomcat=6.0.32
Apache Tomcat=6.0.33
Apache Tomcat=6.0.35
Apache Tomcat=6.0.36
Apache Tomcat=8.0.0-rc1
Apache Tomcat=8.0.0-rc2
Apache Tomcat=8.0.0-rc3
Apache Tomcat=8.0.0-rc4
Apache Tomcat=8.0.0-rc5
Apache Tomcat=8.0.0-rc6
Apache Tomcat=8.0.0-rc7
Apache Tomcat=8.0.0-rc8
Apache Tomcat=8.0.0-rc9

Event History

Feb 26, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
May 14, 2022
Advisory Published
01:10 AM

Frequently Asked Questions

1

What is the severity of CVE-2013-4322?

CVE-2013-4322 has a severity rating that can lead to denial of service attacks.

2

How do I fix CVE-2013-4322?

To fix CVE-2013-4322, upgrade Apache Tomcat to version 6.0.39, 7.0.50, or 8.0.0-RC10 or later.

3

What are the affected versions of Apache Tomcat for CVE-2013-4322?

The affected versions are Apache Tomcat versions prior to 6.0.39, 7.0.50, and 8.0.0-RC10.

4

Can CVE-2013-4322 be exploited remotely?

Yes, attackers can exploit CVE-2013-4322 remotely to cause denial of service.

5

What types of issues does CVE-2013-4322 cause in Apache Tomcat?

CVE-2013-4322 causes issues with processing chunked transfer coding, leading to potential service disruptions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203