Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks
|
|
SecurityTracker Alert ID: 1014365
|
|
SecurityTracker URL: http://securitytracker.com/id?1014365
|
|
CVE Reference: CVE-2005-2090
(Links to External Site)
|
Updated: May 14 2007
|
Original Entry Date: Jul 3 2005
|
Impact: Modification of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 4.1.24, 5.0.19
|
Description: A potential vulnerability was reported in Apache Tomcat when used in conjunction with certain gateway and proxy servers. A remote user can conduct HTTP request smuggling attacks.
If the web server is used in conjunction with a proxy server or application gateway (e.g., cache, firewall) and if there is an input
validation vulnerability in the web server or one of its applications, then a remote user can use HTTP request smuggling techniques
to hijack a target user's request or conduct a variation of a cross-site scripting attack against a target user.
A remote user
can send multiple HTTP requests with specially crafted HTTP headers to the target server via the proxy/gateway server. The requests
may be interpreted differently by the target server than by the proxy/gateway server. As a result, unexpected results may occur.
A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway
server, or conduct cross-site scripting attacks against target users.
Networks that use Tomcat in conjunction with Internet Security
and Acceleration Server, DeleGate, or Sun ONE proxy server may be affected. Other configurations may also be affected.
This
vulnerability was reported by Watchfire.
A description of HTTP request smuggling attacks is available at:
http://www.watchfire.com/resources/HTTP-Request-Smuggling.
pdf
|
Impact: Depending on the associated proxy/gateway server used in conjunction with the target system, a remote user may be able to poison
an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site
scripting attacks against target users.
|
Solution: The vendor has issued fixed versions (4.1.36, 5.5.23, 5.0.HEAD, 6.0.HEAD).
The Apache advisories are available at:
http://tomcat.apache.org/security-4.html
http://t
omcat.apache.org/security-5.html
http://tomcat.apache.org/security-6.html
|
Vendor URL: jakarta.apache.org/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Sat, 2 Jul 2005 02:14:48 -0400
Subject: http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf
|
> Tomcat 4.1.24, 5.0.19
|
|