HP released security bulletin HPSBUX03337 (SSRT102066 rev.1) for HP-UX B.11.31 systems running the HP-UX Apache Web Server Suite, Apache Web Server, Tomcat Servlet Engine, or PHP. The 14 addressed CVEs could enable remote denial of service, man-in-the-middle attacks, remote data modification, and local data modification, with CVSS v2 base scores ranging from 4.3 to 7.5.
HP directed customers to upgrade to HP-UX Web Server Suite v4.05 or later, which updates the bundled Apache, Tomcat, and PHP components to remediated versions. One tracked issue, CVE-2013-5704, affects Apache HTTP Server 2.2.22's mod_headers module and allows remote attackers to bypass configured RequestHeader unset rules by supplying headers in chunked-request trailer fields; Apache stated that this behavior was not a security issue in httpd itself, although downstream vendors issued advisories for affected distributions.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2013-5704 was updated, retaining Apache's position that the behavior was not a security issue in httpd itself and documenting downstream vendor references.
Hewlett-Packard issued HPSBUX03337 (SSRT102066 rev.1) for HP-UX 11i v3 web-server components, including Apache-related CVE-2013-5704. HP directed affected customers to upgrade to HP-UX Web Server Suite v4.05 or later, which includes remediated Apache, Tomcat, and PHP versions.
CVE-2014-0230 was published for an Apache Tomcat denial-of-service flaw triggered when a response is sent before the full request body is read. Remote attackers could repeatedly abort uploads to consume server threads; affected versions were Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9.
CVE-2014-0227 was published for an Apache Tomcat ChunkedInputFilter vulnerability in which malformed chunked transfer coding could cause continued data reads after an error. Remote attackers could use the flaw for HTTP request smuggling or denial of service through resource consumption; affected releases included Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9.
CVE-2014-0075 was published for an integer-overflow vulnerability in Apache Tomcat's ChunkedInputFilter parseChunkHeader function. A remote attacker could send a malformed chunk size in streamed HTTP chunked transfer coding to cause denial of service through resource consumption in Tomcat versions before 6.0.40, 7.0.53, and 8.0.4.
CVE-2014-0099 was published for an integer-overflow flaw in Apache Tomcat's Ascii.java component. A remote attacker could use a crafted Content-Length header to conduct HTTP request smuggling when a vulnerable Tomcat server operated behind a reverse proxy.
CVE-2013-5704 was published for an Apache HTTP Server 2.2.22 mod_headers issue in which a remote attacker could bypass configured RequestHeader unset directives by supplying a header in a chunked-request trailer.
CVE-2013-4286 was published for an Apache Tomcat HTTP request-smuggling vulnerability caused by improper handling of inconsistent request headers in HTTP or AJP connectors. Attackers could manipulate request-length determination using multiple Content-Length headers or both Content-Length and Transfer-Encoding: chunked headers; the flaw was an incomplete fix for CVE-2005-2090.
CVE-2013-4322 was published for an Apache Tomcat denial-of-service flaw in HTTP chunked transfer coding. Crafted streamed chunked data could exploit improper handling of large chunked-data volumes or whitespace in trailer-field header values in affected Tomcat versions.
CVE-2012-3544 was published for an Apache Tomcat denial-of-service flaw caused by improper handling of chunk extensions in HTTP chunked transfer coding. Streaming data with chunk extensions could exhaust resources on affected Tomcat 6 versions before 6.0.37 and Tomcat 7 versions before 7.0.30.
CVE-2012-4534 was published for an Apache Tomcat NIO connector denial-of-service flaw affecting Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 when sendfile and HTTPS were both used. A remote attacker could terminate a connection during response reading to trigger an infinite loop in NioEndpoint.java; fixes were included in Tomcat 6.0.36 and 7.0.28.
CVE-2010-2227 was published for an Apache Tomcat vulnerability in handling invalid HTTP Transfer-Encoding headers. A crafted header could interfere with buffer recycling, causing denial of service or potential sensitive-information disclosure in affected Tomcat 5.5, 6.0, and 7.0 beta versions.
Red Hat published security advisory RHSA-2014:0686. The supplied reference does not include the affected products, vulnerabilities, or remediation details.
Fedora 21's stable repository received tomcat-7.0.59-1.fc21, addressing the CVE-2014-0227 ChunkedInputFilter flaw that could enable resource-exhaustion denial of service and potentially request smuggling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcemarc.info
Open sourcebugzilla.redhat.com
Open sourcerhn.redhat.com
Open sourceh20564.www2.hp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.