Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
| Score | Percentile |
|---|---|
| 44.77% | 97.52% |
No CVSS scores in this advisory.
| Type | Value |
|---|---|
| GHSA | GHSA-qfxv-3ppc-7qg5 ↗ |
| CVE | CVE-2012-3544 ↗ |
| CWE id | Name |
|---|---|
| CWE-20 | Improper Input Validation |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.apache.tomcat:tomcat | >= 6.0.0, < 6.0.37 | 6.0.37 | — |
| maven | org.apache.tomcat:tomcat | >= 7.0.0, < 7.0.30 | 7.0.30 | — |