Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-0099

Опубликовано: 31 мая 2014
Источник: debian
EPSS Средний

Описание

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat8fixed8.0.5-1package
tomcat7fixed7.0.53-1package
tomcat7fixed7.0.28-4+deb7u3wheezypackage
tomcat6fixed6.0.41-1package

Примечания

  • http://svn.apache.org/r1578814

EPSS

Процентиль: 97%
0.3908
Средний

Связанные уязвимости

ubuntu
почти 12 лет назад

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

redhat
почти 12 лет назад

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

nvd
почти 12 лет назад

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

github
почти 4 года назад

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat

fstec
почти 12 лет назад

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить защищаемой информации

EPSS

Процентиль: 97%
0.3908
Средний