Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability

Apache Tomcat is prone to a remote information-disclosure vulnerability because the HTTP/1.0 connector fails to properly handle a NULL byte in URIs when 'allowLinking' is configured.

Remote attackers can exploit this issue to obtain potentially sensitive information.

Note that HTTP/1.0 connector is deprecated; this issue is not scheduled to be fixed.

The issue affects Tomcat 4.1.15 and later.







 

Privacy Statement
Copyright 2007, SecurityFocus