Vulnerability Description
Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | <= 6.0.39 |
Related Weaknesses (CWE)
References
- http://advisories.mageia.org/MGASA-2014-0268.html
- http://linux.oracle.com/errata/ELSA-2014-0865.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150282.h
- http://marc.info/?l=bugtraq&m=141017844705317&w=2
- http://marc.info/?l=bugtraq&m=141390017113542&w=2
- http://marc.info/?l=bugtraq&m=144498216801440&w=2
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://seclists.org/fulldisclosure/2014/May/138
- http://seclists.org/fulldisclosure/2014/May/140
- http://secunia.com/advisories/59121
- http://secunia.com/advisories/59678
- http://secunia.com/advisories/59732
FAQ
What is CVE-2014-0099?
CVE-2014-0099 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to...
How severe is CVE-2014-0099?
CVE-2014-0099 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0099?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.