Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 8931 - [SECURITY] Update Tomcat 4.0.5 to 4.0.6
Summary: [SECURITY] Update Tomcat 4.0.5 to 4.0.6
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Normal critical (vote)
Assignee: Gentoo Security
URL: http://jakarta.apache.org/tomcat
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-10-09 09:22 UTC by Adrian Almenar
Modified: 2002-10-14 22:30 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
tomcat-4.0.6.ebuild (tomcat-4.0.6.ebuild,775 bytes, text/plain)
2002-10-09 09:23 UTC, Adrian Almenar
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Adrian Almenar 2002-10-09 09:22:43 UTC
This is part of the email published on tomcat list: 
 
A security vulnerability has been confirmed to exist in Apache Tomcat 
4.0.x releases (including Tomcat 4.0.5), which allows to use a specially 
crafted URL to return the unprocessed source of a JSP page, or, under 
special circumstances, a static resource which would otherwise have been 
protected by security constraint, without the need for being properly 
authenticated. This is based on a variant of the exploit that was 
disclosed on 09/24/2002. 
 
The cause 
--------- 
 
Using the invoker servlet in conjunction with the default servlet 
(responsible for handling static content in Tomcat) triggers this 
vulnerability. 
 
Who is vulnerable 
----------------- 
 
- All Tomcat 4.0.x releases, except those in which the invoker servlet 
is disabled (this is not the default setting). 
- All Tomcat 4.1.x releases before 4.1.12, except those in which the 
invoker servlet is disabled (this is not the default setting), as 
well as 4.1.12 if and only if the invoker servlet has been enabled. 
The default Tomcat 4.1.12 installation is not vulnerable.
Comment 1 Adrian Almenar 2002-10-09 09:23:40 UTC
Created attachment 4540 [details]
tomcat-4.0.6.ebuild
Comment 2 Maik Schreiber 2002-10-14 22:30:03 UTC
Committed to the tree, thanks.