CVE-2005-3747: Incorrect input validation of HTTP requests

Related Vulnerabilities: CVE-2005-3747  

Debian Bug report logs - #340582
CVE-2005-3747: Incorrect input validation of HTTP requests

version graph

Reported by: Moritz Muehlenhoff <jmm@inutil.org>

Date: Thu, 24 Nov 2005 11:03:07 UTC

Severity: grave

Tags: security

Found in version jetty/5.1.5rc1-6

Fixed in version jetty/5.1.8-1

Done: Philipp Meier <meier@fnogol.de>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Security Team <team@security.debian.org>, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#340582; Package jetty. (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@inutil.org>:
New Bug report received and forwarded. Copy sent to Debian Security Team <team@security.debian.org>, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@inutil.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2005-3747: Incorrect input validation of HTTP requests
Date: Thu, 24 Nov 2005 11:59:44 +0100
Package: jetty
Version: 5.1.5rc1-6
Severity: grave
Tags: security
Justification: user security hole

An input validation error when processing HTTP requests containing specially
crafted characters can be exploited to display the source code of Java
Server pages instead of an expected HTML response.

Please see http://www.frsirt.com/english/advisories/2005/2515 for details.

It's fixed upstream in 5.1.6. This has been assigned CVE-2005-3747, please
mention it in the changelog when fixing it.

Cheers,
        Moritz

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-2-686
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15@euro (charmap=ISO-8859-15)



Bug marked as fixed in version 5.1.8-1, send any further explanations to Moritz Muehlenhoff <jmm@inutil.org> Request was from Philipp Meier <meier@fnogol.de> to control@bugs.debian.org. (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 26 Jun 2007 19:39:22 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 16:31:52 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.