CVE Vulnerabilities

CVE-2014-0099

Published: May 31, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache * 6.0.39 (including)
Tomcat Apache 6 (including) 6 (including)
Tomcat Apache 6.0 (including) 6.0 (including)
Tomcat Apache 6.0.0 (including) 6.0.0 (including)
Tomcat Apache 6.0.0-alpha (including) 6.0.0-alpha (including)
Tomcat Apache 6.0.1 (including) 6.0.1 (including)
Tomcat Apache 6.0.1-alpha (including) 6.0.1-alpha (including)
Tomcat Apache 6.0.2 (including) 6.0.2 (including)
Tomcat Apache 6.0.2-alpha (including) 6.0.2-alpha (including)
Tomcat Apache 6.0.2-beta (including) 6.0.2-beta (including)
Tomcat Apache 6.0.3 (including) 6.0.3 (including)
Tomcat Apache 6.0.4 (including) 6.0.4 (including)
Tomcat Apache 6.0.4-alpha (including) 6.0.4-alpha (including)
Tomcat Apache 6.0.5 (including) 6.0.5 (including)
Tomcat Apache 6.0.6 (including) 6.0.6 (including)
Tomcat Apache 6.0.6-alpha (including) 6.0.6-alpha (including)
Tomcat Apache 6.0.7 (including) 6.0.7 (including)
Tomcat Apache 6.0.7-alpha (including) 6.0.7-alpha (including)
Tomcat Apache 6.0.7-beta (including) 6.0.7-beta (including)
Tomcat Apache 6.0.8 (including) 6.0.8 (including)
Tomcat Apache 6.0.8-alpha (including) 6.0.8-alpha (including)
Tomcat Apache 6.0.9 (including) 6.0.9 (including)
Tomcat Apache 6.0.9-beta (including) 6.0.9-beta (including)
Tomcat Apache 6.0.10 (including) 6.0.10 (including)
Tomcat Apache 6.0.11 (including) 6.0.11 (including)
Tomcat Apache 6.0.12 (including) 6.0.12 (including)
Tomcat Apache 6.0.13 (including) 6.0.13 (including)
Tomcat Apache 6.0.14 (including) 6.0.14 (including)
Tomcat Apache 6.0.15 (including) 6.0.15 (including)
Tomcat Apache 6.0.16 (including) 6.0.16 (including)
Tomcat Apache 6.0.17 (including) 6.0.17 (including)
Tomcat Apache 6.0.18 (including) 6.0.18 (including)
Tomcat Apache 6.0.19 (including) 6.0.19 (including)
Tomcat Apache 6.0.20 (including) 6.0.20 (including)
Tomcat Apache 6.0.24 (including) 6.0.24 (including)
Tomcat Apache 6.0.26 (including) 6.0.26 (including)
Tomcat Apache 6.0.27 (including) 6.0.27 (including)
Tomcat Apache 6.0.28 (including) 6.0.28 (including)
Tomcat Apache 6.0.29 (including) 6.0.29 (including)
Tomcat Apache 6.0.30 (including) 6.0.30 (including)
Tomcat Apache 6.0.31 (including) 6.0.31 (including)
Tomcat Apache 6.0.32 (including) 6.0.32 (including)
Tomcat Apache 6.0.33 (including) 6.0.33 (including)
Tomcat Apache 6.0.35 (including) 6.0.35 (including)
Tomcat Apache 6.0.36 (including) 6.0.36 (including)
Tomcat Apache 6.0.37 (including) 6.0.37 (including)
Red Hat Enterprise Linux 6 RedHat tomcat6-0:6.0.24-72.el6_5 *
Red Hat Enterprise Linux 7 RedHat tomcat-0:7.0.42-6.el7_0 *
Red Hat JBoss BPMS 6.0 RedHat jbossweb *
Red Hat JBoss BRMS 6.0 RedHat jbossweb *
Red Hat JBoss Data Grid 6.3 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.0 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.1 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat6-0:6.0.37-20_patch_04.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat7-0:7.0.40-14_patch_03.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat6-0:6.0.37-29_patch_05.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat7-0:7.0.40-11_patch_03.ep6.el6 *
Red Hat JBoss Fuse Service Works 6.0 RedHat jbossweb *
Red Hat JBoss Operations Network 3.2 RedHat *
Red Hat JBoss Portal 6.2 RedHat jbossweb *
Red Hat JBoss Web Server 2.0 RedHat tomcat6 *
Red Hat JBoss Web Server 2.0 RedHat tomcat7 *
Tomcat6 Ubuntu lucid *
Tomcat6 Ubuntu precise *
Tomcat6 Ubuntu saucy *
Tomcat6 Ubuntu trusty *
Tomcat6 Ubuntu upstream *
Tomcat7 Ubuntu precise *
Tomcat7 Ubuntu saucy *
Tomcat7 Ubuntu trusty *
Tomcat7 Ubuntu upstream *
Tomcat8 Ubuntu upstream *

References