Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 188869

Summary: www-servers/tomcat CVE-2007-3385: Handling of \" in cookies
Product: Gentoo Security Reporter: William L. Thomson Jr. (RETIRED) <wltjr>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: java
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385
Whiteboard:
Package list:
Runtime testing required: ---

Description William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:45:47 UTC
Severity:
Low (Session Hi-jacking)

Vendor:
The Apache Software Foundation

Versions Affected:
6.0.0 to 6.0.13
5.5.0 to 5.5.24
5.0.0 to 5.0.30
4.1.0 to 4.1.36
3.3 to 3.3.2

Description:
Tomcat incorrectly handles the character sequence \" in a cookie
value. In some circumstances this can lead to the leaking of
information such as session ID to an attacker.

Mitigation:
Upgrade to 6.0.14
Comment 1 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:49:18 UTC
6.0.14 is in tree, recently requested stabilization of 6.0.13. We might rush stabilize 6.0.14. No changes to package short of upstream code modifications, which mostly seem to be bug fixes and etc.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-24 14:13:53 UTC

*** This bug has been marked as a duplicate of bug 188871 ***