Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 188869 - www-servers/tomcat CVE-2007-3385: Handling of \" in cookies
Summary: www-servers/tomcat CVE-2007-3385: Handling of \" in cookies
Status: RESOLVED DUPLICATE of bug 188871
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-14 17:45 UTC by William L. Thomson Jr. (RETIRED)
Modified: 2011-10-30 22:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:45:47 UTC
Severity:
Low (Session Hi-jacking)

Vendor:
The Apache Software Foundation

Versions Affected:
6.0.0 to 6.0.13
5.5.0 to 5.5.24
5.0.0 to 5.0.30
4.1.0 to 4.1.36
3.3 to 3.3.2

Description:
Tomcat incorrectly handles the character sequence \" in a cookie
value. In some circumstances this can lead to the leaking of
information such as session ID to an attacker.

Mitigation:
Upgrade to 6.0.14
Comment 1 William L. Thomson Jr. (RETIRED) gentoo-dev 2007-08-14 17:49:18 UTC
6.0.14 is in tree, recently requested stabilization of 6.0.13. We might rush stabilize 6.0.14. No changes to package short of upstream code modifications, which mostly seem to be bug fixes and etc.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-24 14:13:53 UTC

*** This bug has been marked as a duplicate of bug 188871 ***