CVE-2011-3375
published 2012-01-19CVE-2011-3375: Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
6.69%
93.2th percentile
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
ghsa·2022-05-17
CVE-2011-3375 [MEDIUM] CWE-200 Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
OSV
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
osv·2022-05-17
CVE-2011-3375 [MEDIUM] Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Red Hat
kernel: epoll: can leak file descriptors when returning -ELOOP
vendor_redhat·2012-03-27·CVSS 4.9
CVE-2012-3375 [MEDIUM] kernel: epoll: can leak file descriptors when returning -ELOOP
kernel: epoll: can leak file descriptors when returning -ELOOP
The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, since updates fixing CVE-2011-1083 contained a corrected patch that did not introduce this regression.
This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-1061.html, and R
VMware
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
vendor_vmware·2012-03-15·CVSS 7.2
CVE-2010-0405 [HIGH] VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
VMSA-2012-0005: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
a. VMware Tools Display Driver Privilege Escalation The VMware XPDM and WDDM display drivers contain buffer overflow vulnerabilities and the XPDM display driver does not properly check for NULL pointers. Exploitation of these issues may lead to local privilege escalation on Windows-based Guest Operating Systems. VMware would like to thank Tarjei Mandt for reporting theses issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2012-1509 (XPDM buffer overrun), CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null pointer dereference) to these issues. Note: CVE-2012-1509 do
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2012-02-13·CVSS 5.0
CVE-2011-3375 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Tomcat could be made to crash or expose sensitive information if it
received specially crafted network traffic.
It was discovered that Tomcat incorrectly performed certain caching and
recycling operations. A remote attacker could use this flaw to obtain read
access to IP address and HTTP header information in certain cases. This
issue only applied to Ubuntu 11.10. (CVE-2011-3375)
It was discovered that Tomcat computed hash values for form parameters
without restricting the ability to trigger hash collisions predictably.
A remote attacker could cause a denial of service by sending many crafted
parameters. (CVE-2011-4858)
It was discovered that Tomcat incorrectly handled parameters. A remote
attacker could cause a denial of service by sending reques
Red Hat
tomcat: information disclosure due to improper response and request object recycling
vendor_redhat·2012-01-17·CVSS 5.0
CVE-2011-3375 [MEDIUM] tomcat: information disclosure due to improper response and request object recycling
tomcat: information disclosure due to improper response and request object recycling
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
bugzilla·2012-07-04·CVSS 4.9
CVE-2012-3375 [MEDIUM] CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
CVE-2012-3375 kernel: epoll: can leak file descriptors when returning -ELOOP
An epoll_ctl(,EPOLL_CTL_ADD,,) operation can return '-ELOOP' to prevent circular epoll dependencies from being created. However, in that case we do not properly clear the 'tfile_check_list'.
An unprivileged local user could use this flaw to crash the system.
This is a regression introduced via the CVE-2011-1083 (bug #681578) fix (commit 28d82dc1c4edbc352129f97f4ca22624d1fe61de):
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=28d82dc1c4edbc352129f97f4ca22624d1fe61de
Upstream fix:
13d518074a952d33d47c428419693f63389547e9
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=13d518074a952d33d47c428419693f63389547e9
References:
https://lkml.org/lkml/2012/
Bugzilla
CVE-2011-3375 tomcat6: information disclosure due to improper response and request object recycling [fedora-all]
bugzilla·2012-01-22·CVSS 5.0
CVE-2011-3375 [MEDIUM] CVE-2011-3375 tomcat6: information disclosure due to improper response and request object recycling [fedora-all]
CVE-2011-3375 tomcat6: information disclosure due to improper response and request object recycling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedorapr
Bugzilla
CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling
bugzilla·2012-01-17·CVSS 5.0
CVE-2011-3375 [MEDIUM] CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling
CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling
From the upstream advisory [1]:
For performance reasons, information parsed from a request is often
cached in two places: the internal request object and the internal
processor object. These objects are not recycled at exactly the same time.
When certain errors occur that needed to be added to the access log, the
access logging process triggers the re-population of the request object
after it has been recycled. However, the request object was not recycled
before being used for the next request. That lead to information leakage
(e.g. remote IP address, HTTP headers) from the previous request to the
next request.
The issue was resolved be ensuring that the request and response objects
were r
2012-01-19
Published