Debian Bug report logs -
#340582
CVE-2005-3747: Incorrect input validation of HTTP requests
Reported by: Moritz Muehlenhoff <jmm@inutil.org>
Date: Thu, 24 Nov 2005 11:03:07 UTC
Severity: grave
Tags: security
Found in version jetty/5.1.5rc1-6
Fixed in version jetty/5.1.8-1
Done: Philipp Meier <meier@fnogol.de>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Debian Security Team <team@security.debian.org>, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
:
Bug#340582
; Package jetty
.
(full text, mbox, link).
Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>
:
New Bug report received and forwarded. Copy sent to Debian Security Team <team@security.debian.org>, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Package: jetty
Version: 5.1.5rc1-6
Severity: grave
Tags: security
Justification: user security hole
An input validation error when processing HTTP requests containing specially
crafted characters can be exploited to display the source code of Java
Server pages instead of an expected HTML response.
Please see http://www.frsirt.com/english/advisories/2005/2515 for details.
It's fixed upstream in 5.1.6. This has been assigned CVE-2005-3747, please
mention it in the changelog when fixing it.
Cheers,
Moritz
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-2-686
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15@euro (charmap=ISO-8859-15)
Bug marked as fixed in version 5.1.8-1, send any further explanations to Moritz Muehlenhoff <jmm@inutil.org>
Request was from Philipp Meier <meier@fnogol.de>
to control@bugs.debian.org
.
(full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org
.
(Tue, 26 Jun 2007 19:39:22 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Wed Jun 19 16:31:52 2019;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.