Bug 880347 - (CVE-2014-0099) VUL-0: CVE-2014-0099: Apache Tomcat: Request smuggling via malicious content length header
VUL-0: CVE-2014-0099: Apache Tomcat: Request smuggling via malicious content ...
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Bo Maryniuk
Security Team bot
maint:released:sle11-sp1:58154 maint...
Depends on:
  Show dependency treegraph
Reported: 2014-05-28 13:25 UTC by Sebastian Krahmer
Modified: 2014-08-13 17:04 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2014-05-28 22:00:19 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2014-06-02 12:39:55 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-06-16.
When done, reassign the bug to security-team@suse.de.
Comment 3 SMASH SMASH 2014-06-02 14:45:30 UTC
Affected packages:

SLE-11-SP3: tomcat6
Comment 5 Marcus Meissner 2014-08-13 08:25:16 UTC
Comment 6 Swamp Workflow Management 2014-08-13 17:04:59 UTC
SUSE-SU-2014:1015-1: An update that solves 5 vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 844689,865746,880346,880347,880348,881700
CVE References: CVE-2012-3544,CVE-2013-4322,CVE-2014-0096,CVE-2014-0099,CVE-2014-0119
Sources used:
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    libtcnative-1-0-1.3.3-12.2.1, tomcat6-6.0.41-0.43.1
SUSE Linux Enterprise Server 11 SP3 (src):    libtcnative-1-0-1.3.3-12.2.1, tomcat6-6.0.41-0.43.1