Tomcat hangs 2004-02-12 - By Chris Rolfe
Back Hello,
I posted a query last week about Tomcat 4.0.6 under OS X hanging, but haven't seen any response (was: SocketInputStream hanging Tomcat 4.0.6).
Is there anything more I can do ( more information I can provide, for example ) to illicit feedback from the list or the developer of the code section?
This appears to be a vulnerability in Tomcat 4.0.6 - 4.1.x.
-- ---- ---- ---- The problem:
Stage 1: According to the catalina log, SocketInputStream.readHeader is throwing ArrayIndexOutOfBounds exceptions at line 487.
Stage 2: Successive throws eventually cause Tomcat to respond to all requests with error 400: bad request.
The original http requests stemmed from one IP range, whose access I've since disabled. I'm very concerned that a single user was able to bring down the server.
Does anyone have a feel for what's happening here?
Chris
-- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- ------ To unsubscribe, e-mail: tomcat-user-unsubscribe@(protected) For additional commands, e-mail: tomcat-user-help@(protected)
|
|