Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 374619

Summary: www-servers/tomcat: session hijack (CVE-2010-4312)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: java
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B4 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 322979    

Description GLSAMaker/CVETool Bot gentoo-dev 2011-07-10 00:20:32 UTC
CVE-2010-4312 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312):
  The default configuration of Apache Tomcat 6.x does not include the HTTPOnly
  flag in a Set-Cookie header, which makes it easier for remote attackers to
  hijack a session via script access to a cookie.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2011-07-10 00:21:34 UTC
Can you punt anything <www-servers/tomcat-6.0.32-r2?
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2011-10-22 17:44:45 UTC
Ignoring comment #1, what's your plan here? I was unable to find a statement from upstream, but Red Hat's security team issued a statement:

https://bugzilla.redhat.com/show_bug.cgi?id=658267
Comment 3 Miroslav Šulc gentoo-dev 2011-10-22 18:54:52 UTC
(In reply to comment #1)
> Can you punt anything <www-servers/tomcat-6.0.32-r2?

done, except www-servers/tomcat-6.0.32-r2 has been never stable so it's gone too, remained www-servers/tomcat-6.0.32-r1 until www-servers/tomcat-6.0.33 is stabilized
Comment 4 Miroslav Šulc gentoo-dev 2012-03-25 20:25:10 UTC
no affected version in the tree anymore
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2012-06-24 14:12:51 UTC
This issue was resolved and addressed in
 GLSA 201206-24 at http://security.gentoo.org/glsa/glsa-201206-24.xml
by GLSA coordinator Tobias Heinlein (keytoaster).