Description
Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9Confidentiality: None
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
5OSVImproper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat↗2022-05-14 ▶ GHSAImproper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat↗2022-05-14 ▶ OSVtomcat6, tomcat7 vulnerabilities↗2014-07-30 ▶ OSVCVE-2014-0099: Integer overflow in java/org/apache/tomcat/util/buf/Ascii↗2014-05-31 ▶ CVEListCVE-2014-0099: Integer overflow in java/org/apache/tomcat/util/buf/Ascii↗2014-05-31 ▶ 📋Vendor Advisories
3UbuntuTomcat vulnerabilities↗2014-07-30 ▶ Red HatTomcat/JBossWeb: Request smuggling via malicious content length header↗2014-05-27 ▶ ApacheApache tomcat: CVE-2014-0099↗ ▶ 💬Community
2BugzillaCVE-2014-0099 Apache Tomcat: Request smuggling via malicious content length header [fedora-all]↗2014-05-28 ▶ BugzillaCVE-2014-0099 Tomcat/JBossWeb: Request smuggling via malicious content length header↗2014-05-28 ▶