<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>173122</bug_id>
          
          <creation_ts>2007-04-02 11:47 0000</creation_ts>
          <short_desc>www-servers/tomcat directory traversal (CVE-2007-0450)</short_desc>
          <delta_ts>2007-05-02 03:03:43 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0450</bug_file_loc>
          <status_whiteboard>B4 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>173150</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>java@gentoo.org</cc>
    
    <cc>py@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-02 11:47:19 0000</bug_when>
            <thetext>Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) &quot;/&quot; (slash), (2) &quot;\&quot; (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-02 11:47:43 0000</bug_when>
            <thetext>Java please advise.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-02 11:57:12 0000</bug_when>
            <thetext>*** Bug 173125 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-04-02 12:30:04 0000</bug_when>
            <thetext>It&apos;s the maintainer&apos;s call :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-04-02 13:31:55 0000</bug_when>
            <thetext>I have no problem with stabilization of 5.5.23 or 6.0.10. However both have been migrated to split-ant, and split-ant and etc has not been stabilized yet. So ebuild might need to be modified before stabilized.

Now for what&apos;s it&apos;s worth I can&apos;t replicate this problem at all. I have tried on machines that should be vulnerable but aren&apos;t At best with the exploit url modified for my domain and etc, I get a blank page. From both 5.5.20, and 6.0.10.

But I am all for stabilizing the current versions of Tomcat. 6.0.11 is likely to release later this week.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-04-02 16:32:59 0000</bug_when>
            <thetext>Ok, 5.5.23 has been updated to be non-split ant aware. So it can be stabilized ASAP once deps are stabilized. To address the security concerns, that I still have yet to be able to replicate.

As for 6.0.10, let&apos;s hold off. There is a mem leak in the nio code, and an upcoming 6.0.11 with that fix and some others. Not to mention only 5.5.x is stable. So that&apos;s our main concern per vulnerability.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2007-04-02 16:34:27 0000</bug_when>
            <thetext>(In reply to comment #5)
&gt; Ok, 5.5.23 has been updated to be non-split ant aware. So it can be stabilized
&gt; ASAP once deps are stabilized. To address the security concerns, that I still
&gt; have yet to be able to replicate.
&gt; 

Adding arches.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-04-03 07:40:35 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-04-07 00:35:50 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2007-04-09 00:32:29 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; amd64 stable
&gt; 

Just to note that all arches are done now and security can do their magic.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-04-11 10:39:28 0000</bug_when>
            <thetext>Thx.

This one is ready for GLSA decision.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-04-23 19:57:23 0000</bug_when>
            <thetext>i vote yes since attemps to read parent directories is very common agains webapps.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-04-24 19:49:27 0000</bug_when>
            <thetext>I vote yes, same reason as Falco - very common attack, very common webserver.  Changing status and submitting request.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-05-02 03:03:43 0000</bug_when>
            <thetext>GLSA 200705-03, thanks everybody</thetext>
          </long_desc>
      
    </bug>

</bugzilla>