MGASA-2014-0110
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 28 Feb 2014, 18:59
Last modified:16 Apr 2026, 06:25
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
28 Feb 2014, 18:59
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated
Description
Updated tomcat packages fix CVE-2014-0050 Updated tomcat packages fix security vulnerability: It was discovered that the Apache Commons FileUpload package for Java could enter an infinite loop while processing a multipart request with a crafted Content-Type, resulting in a denial-of-service condition (CVE-2014-0050). Tomcat 7 includes an embedded copy of the Apache Commons FileUpload package, and was affected as well.
Affected Systems
- mageia•tomcat
< 7.0.41-5.mga3
- mageia•tomcat
< 7.0.47-1.2.mga4