ICEfaces
  1. ICEfaces
  2. ICE-10023

Fix CVE-2014-0050 DoS with malformed Content-Type header and multipart request processing

    Details

    • Assignee Priority:
      P1

      Description

      ICEfaces FileEntry makes use of an embedded copy of commons-fileupload, so is vulnerable to the following:

      MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0050

        Issue Links

          Activity

            People

            • Assignee:
              Mircea Toma
              Reporter:
              Ted Goddard
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: