CVE-2014-0099

Apache Tomcat <6.0.40, <7.0.53, <8.0.4 - HTTP Request Smuggling

Title source: llm
STIX 2.1

Description

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

References (49)

Core 49
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0765.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0675.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0720.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0268.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59121
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59732
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59835
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21681528
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:052
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/May/140
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59849
Various Sources x_refsource_confirm
http://linux.oracle.com/errata/ELSA-2014-0865.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:084
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59678
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141017844705317&w=2
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532221/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67668
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3530
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532218/100/0/threaded
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-7.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:053
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=141390017113542&w=2
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-February/150282.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-8.html
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21678231
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59873
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030302
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=144498216801440&w=2
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3447
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60729
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60793
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/May/138
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21680603

Scores

EPSS 0.3786
EPSS Percentile 97.3%

Details

CWE
CWE-189
Status published
Products (37)
apache/tomcat 6
apache/tomcat 6.0
apache/tomcat 6.0.0 (2 CPE variants)
apache/tomcat 6.0.1 (2 CPE variants)
apache/tomcat 6.0.2 (3 CPE variants)
apache/tomcat 6.0.3
apache/tomcat 6.0.4 (2 CPE variants)
apache/tomcat 6.0.5
apache/tomcat 6.0.6 (2 CPE variants)
apache/tomcat 6.0.7 (3 CPE variants)
... and 27 more
Published May 31, 2014
Tracked Since Feb 18, 2026