Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 374619 - www-servers/tomcat: session hijack (CVE-2010-4312)
Summary: www-servers/tomcat: session hijack (CVE-2010-4312)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [glsa]
Keywords:
Depends on:
Blocks: 322979
  Show dependency tree
 
Reported: 2011-07-10 00:20 UTC by GLSAMaker/CVETool Bot
Modified: 2012-06-24 14:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-07-10 00:20:32 UTC
CVE-2010-4312 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312):
  The default configuration of Apache Tomcat 6.x does not include the HTTPOnly
  flag in a Set-Cookie header, which makes it easier for remote attackers to
  hijack a session via script access to a cookie.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2011-07-10 00:21:34 UTC
Can you punt anything <www-servers/tomcat-6.0.32-r2?
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2011-10-22 17:44:45 UTC
Ignoring comment #1, what's your plan here? I was unable to find a statement from upstream, but Red Hat's security team issued a statement:

https://bugzilla.redhat.com/show_bug.cgi?id=658267
Comment 3 Miroslav Šulc gentoo-dev 2011-10-22 18:54:52 UTC
(In reply to comment #1)
> Can you punt anything <www-servers/tomcat-6.0.32-r2?

done, except www-servers/tomcat-6.0.32-r2 has been never stable so it's gone too, remained www-servers/tomcat-6.0.32-r1 until www-servers/tomcat-6.0.33 is stabilized
Comment 4 Miroslav Šulc gentoo-dev 2012-03-25 20:25:10 UTC
no affected version in the tree anymore
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2012-06-24 14:12:51 UTC
This issue was resolved and addressed in
 GLSA 201206-24 at http://security.gentoo.org/glsa/glsa-201206-24.xml
by GLSA coordinator Tobias Heinlein (keytoaster).