SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Server/CGI)  >   Tomcat Vendors:   Apache Software Foundation
Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks
SecurityTracker Alert ID:  1014365
SecurityTracker URL:  http://securitytracker.com/id/1014365
CVE Reference:   CVE-2005-2090   (Links to External Site)
Updated:  May 14 2007
Original Entry Date:  Jul 3 2005
Impact:   Modification of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 4.1.24, 5.0.19
Description:   A potential vulnerability was reported in Apache Tomcat when used in conjunction with certain gateway and proxy servers. A remote user can conduct HTTP request smuggling attacks.

If the web server is used in conjunction with a proxy server or application gateway (e.g., cache, firewall) and if there is an input validation vulnerability in the web server or one of its applications, then a remote user can use HTTP request smuggling techniques to hijack a target user's request or conduct a variation of a cross-site scripting attack against a target user.

A remote user can send multiple HTTP requests with specially crafted HTTP headers to the target server via the proxy/gateway server. The requests may be interpreted differently by the target server than by the proxy/gateway server. As a result, unexpected results may occur. A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.

Networks that use Tomcat in conjunction with Internet Security and Acceleration Server, DeleGate, or Sun ONE proxy server may be affected. Other configurations may also be affected.

This vulnerability was reported by Watchfire.

A description of HTTP request smuggling attacks is available at:

http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf

Impact:   Depending on the associated proxy/gateway server used in conjunction with the target system, a remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.
Solution:   The vendor has issued fixed versions (4.1.36, 5.5.23, 5.0.HEAD, 6.0.HEAD).

The Apache advisories are available at:

http://tomcat.apache.org/security-4.html
http://tomcat.apache.org/security-5.html
http://tomcat.apache.org/security-6.html

Vendor URL:  jakarta.apache.org/ (Links to External Site)
Cause:   State error
Underlying OS:   Linux (Any), UNIX (Any), Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
May 14 2007 (Red Hat Issues Fix) Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 5.
May 21 2007 (Red Hat Issues Fix) Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Application Server.
May 24 2007 (Red Hat Issues Fix) Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Developer Suite.
May 24 2007 (Red Hat Issues Fix for JBoss) Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks   (bugzilla@redhat.com)
Red Hat has released a fix for JBoss.
Jul 2 2008 (Sun Issues Fix for Solaris) Tomcat May Allow Remote Users to Conduct HTTP Response Smuggling Attacks
Sun has issued a fix for Solaris 10.



 Source Message Contents

Date:  Sat, 2 Jul 2005 02:14:48 -0400
Subject:  http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf



> Tomcat 4.1.24, 5.0.19
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC