Jetty Unspecified HTTP Response Splitting Vulnerability
BID:26696
Info
Jetty Unspecified HTTP Response Splitting Vulnerability
| Bugtraq ID: | 26696 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5615 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2007 12:00AM |
| Updated: | Apr 13 2015 09:50PM |
| Credit: | Tomasz Kuczynski is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP2 Jetty Jetty 6.0.2 Jetty Jetty 6.0.1 Jetty Jetty 6.1.5 Jetty Jetty 6.1.4 Jetty Jetty 6.1.3 Jetty Jetty 6.1.2 Jetty Jetty 6.1.1 Jetty Jetty 6.1.0pre3 Jetty Jetty 6.1.0pre2 |
| Not Vulnerable: |
Jetty Jetty 6.1.6 |
Discussion
Jetty Unspecified HTTP Response Splitting Vulnerability
Jetty is prone to an HTTP-response-splitting vulnerability because it fails to sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
This issue affects versions prior to Jetty 6.1.6.
Jetty is prone to an HTTP-response-splitting vulnerability because it fails to sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
This issue affects versions prior to Jetty 6.1.6.
Exploit / POC
Jetty Unspecified HTTP Response Splitting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Jetty Unspecified HTTP Response Splitting Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Jetty Jetty 6.1.0pre2
Jetty Jetty 6.1.4
Jetty Jetty 6.1.3
Jetty Jetty 6.1.1
Jetty Jetty 6.1.5
Jetty Jetty 6.1.2
Jetty Jetty 6.1.0pre3
Jetty Jetty 6.0.1
Jetty Jetty 6.0.2
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Jetty Jetty 6.1.0pre2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.4
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.3
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.1
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.5
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.1.0pre3
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.0.1
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
Jetty Jetty 6.0.2
-
Jetty jetty-6.1.6.zip
http://dist.codehaus.org/jetty/jetty-6.1.6/jetty-6.1.6.zip
References
Jetty Unspecified HTTP Response Splitting Vulnerability
References:
References:
- Jetty Changelog (Jetty)
- Jetty Homepage (Jetty)
- Vulnerability Note VU#212984 (US-CERT)