Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
BID:28483
Info
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
| Bugtraq ID: | 28483 |
| Class: | Design Error |
| CVE: |
CVE-2005-4836 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2007 12:00AM |
| Updated: | Mar 27 2008 09:49PM |
| Credit: | Unknown |
| Vulnerable: |
Apache Tomcat 4.1.37 Apache Tomcat 4.1.36 Apache Tomcat 4.1.36 Apache Tomcat 4.1.34 Apache Tomcat 4.1.34 Apache Tomcat 4.1.32 Apache Tomcat 4.1.31 Apache Tomcat 4.1.30 Apache Tomcat 4.1.29 Apache Tomcat 4.1.28 Apache Tomcat 4.1.24 |
| Not Vulnerable: | |
Discussion
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability because the HTTP/1.0 connector fails to properly handle a NULL byte in URIs when 'allowLinking' is configured.
Remote attackers can exploit this issue to obtain potentially sensitive information.
Note that HTTP/1.0 connector is deprecated; this issue is not scheduled to be fixed.
The issue affects Tomcat 4.1.15 and later.
Apache Tomcat is prone to a remote information-disclosure vulnerability because the HTTP/1.0 connector fails to properly handle a NULL byte in URIs when 'allowLinking' is configured.
Remote attackers can exploit this issue to obtain potentially sensitive information.
Note that HTTP/1.0 connector is deprecated; this issue is not scheduled to be fixed.
The issue affects Tomcat 4.1.15 and later.
Exploit / POC
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
Attackers may launch attacks through a browser.
Attackers may launch attacks through a browser.
Solution / Fix
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
References:
References:
- Apache Tomcat 4.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)