Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 188868 - www-servers/tomcat CVE-2007-3382: Handling of cookies containing a ' character
Summary: www-servers/tomcat CVE-2007-3382: Handling of cookies containing a ' character
Status: RESOLVED DUPLICATE of bug 188871
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-14 17:45 UTC by William L. Thomson Jr. (RETIRED)
Modified: 2011-10-30 22:37 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:45:45 UTC
Severity:
Low (Session Hi-jacking)

Vendor:
The Apache Software Foundation

Versions Affected:
6.0.0 to 6.0.13
5.5.0 to 5.5.24
5.0.0 to 5.0.30
4.1.0 to 4.1.36
3.3 to 3.3.2

Description:
Tomcat incorrectly treats a single quote character (') in a cookie
value as a delimiter. In some circumstances this can lead to the
leaking of information such as session ID to an attacker.

Mitigation:
Upgrade to 6.0.14
Comment 1 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:49:14 UTC
6.0.14 is in tree, recently requested stabilization of 6.0.13. We might rush stabilize 6.0.14. No changes to package short of upstream code modifications, which mostly seem to be bug fixes and etc.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-24 14:14:31 UTC

*** This bug has been marked as a duplicate of bug 188871 ***