ALAS-2016-736

Related Vulnerabilities: CVE-2016-3092  

A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long.

ALAS-2016-736


Amazon Linux AMI Security Advisory: ALAS-2016-736
Advisory Release Date: 2016-08-17 13:30 Pacific
Advisory Updated Date: 2016-08-17 13:30 Pacific
Severity: Medium
References: CVE-2016-3092 

Issue Overview:

A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long.


Affected Packages:

tomcat7, tomcat8


Issue Correction:
Run yum update tomcat7 to update your system.
Run yum update tomcat8 to update your system.

New Packages:
noarch:
    tomcat7-servlet-3.0-api-7.0.70-1.18.amzn1.noarch
    tomcat7-docs-webapp-7.0.70-1.18.amzn1.noarch
    tomcat7-log4j-7.0.70-1.18.amzn1.noarch
    tomcat7-jsp-2.2-api-7.0.70-1.18.amzn1.noarch
    tomcat7-javadoc-7.0.70-1.18.amzn1.noarch
    tomcat7-admin-webapps-7.0.70-1.18.amzn1.noarch
    tomcat7-el-2.2-api-7.0.70-1.18.amzn1.noarch
    tomcat7-webapps-7.0.70-1.18.amzn1.noarch
    tomcat7-lib-7.0.70-1.18.amzn1.noarch
    tomcat7-7.0.70-1.18.amzn1.noarch
    tomcat8-lib-8.0.36-1.62.amzn1.noarch
    tomcat8-el-3.0-api-8.0.36-1.62.amzn1.noarch
    tomcat8-jsp-2.3-api-8.0.36-1.62.amzn1.noarch
    tomcat8-webapps-8.0.36-1.62.amzn1.noarch
    tomcat8-8.0.36-1.62.amzn1.noarch
    tomcat8-docs-webapp-8.0.36-1.62.amzn1.noarch
    tomcat8-log4j-8.0.36-1.62.amzn1.noarch
    tomcat8-javadoc-8.0.36-1.62.amzn1.noarch
    tomcat8-servlet-3.1-api-8.0.36-1.62.amzn1.noarch
    tomcat8-admin-webapps-8.0.36-1.62.amzn1.noarch

src:
    tomcat7-7.0.70-1.18.amzn1.src
    tomcat8-8.0.36-1.62.amzn1.src