Infinite loop in Apache Commons FileUpload - CVE-2014-0050

 

Infinite loop in Apache Commons FileUpload - CVE-2014-0050

Published: January 23, 2017 / Updated: April 15, 2019


Vulnerability identifier: #VU5233
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0050
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS conditions on the target system.

The weakness exists due to boundary error when handling Content-Type HTTP header for multipart requests. By sending a specially crafted Content-Type header, containing 4092 characters in "boundary" field, a remote attacker can cause the application to enter into an infinite loop.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Note: the vulnerability was being actively exploited.

Affected software

Apache Commons FileUpload
Apache Struts
Debian Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
FlashSystem V840 9846-AE1 & 9848-AE1
Integration Designer
Sterling Field Sales
IBM Sterling Order Management
Sterling Web Channel
Sterling Selling and Fulfillment Foundation
IBM App Connect for Healthcare
JBoss Enterprise Application Platform
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700

How to mitigate CVE-2014-0050

Update Apache Struts to version 2.3.16.1.
For Apache Commons FileUpload install version 1.3.1.

Apache Commons FileUpload - update to 1.3.1
Apache Struts - update to 2.3.16.1
Sterling Field Sales - addressed in versions SFS9.0-SFP3, SFS9.1.0- SFP3, SFS9.2.0- SFP3, SFS9.2.1- SFP3
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Storwize V3500 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.8, 7.2.0.6, 7.3.0.3
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Sterling Order Management - update to 8.5- SFP3
Sterling Web Channel - addressed in versions 9.0.0-FP6, 9.1.0-FP3
Sterling Selling and Fulfillment Foundation - addressed in versions 9.0.0- SFP3, 9.1.0- SFP3, 9.2.0- SFP3, 9.2.1-SFP3, 9.3.0- SFP2
IBM Security Verify Governance - update to 10.0.2.0.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins