SciLinux: CVE-2007-2449 tomcat SL5.x i386/x86_64
Summary
Date: Tue, 18 Sep 2007 15:47:14 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for tomcat on SL5.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Moderate: tomcat security updateIssue date: 2007-07-17CVE Names: CVE-2007-2449 CVE-2007-2450 CVE-2005-2090 CVE-2006-7195 CVE-2007-0450Some JSPs within the 'examples' web application did not escape userprovided data. If the JSP examples were accessible, this flaw could allow aremote attacker to perform cross-site scripting attacks (CVE-2007-2449).Note: it is recommended the 'examples' web application not be installed ona production system.The Manager and Host Manager web applications did not escape user provideddata. If a user is logged in to the Manager or Host Manager webapplication, an attacker could perform a cross-site scripting attack (CVE-2007-2450).Tomcat was found to accept multiple content-length headers in arequest. This could allow attackers to poison a web-cache, bypass webapplication firewall protection, or conduct cross-site scripting attacks.(CVE-2005-2090)Tomcat permitted various characters as path delimiters. If Tomcat was usedbehind certain proxies and configured to only proxy some contexts, anattacker could construct an HTTP request to work around the contextrestriction and potentially access non-proxied content. (CVE-2007-0450)The implict-objects.jsp file distributed in the examples webapp displayed anumber of unfiltered header values. If the JSP examples were accessible,this flaw could allow a remote attacker to perform cross-site scriptingattacks. (CVE-2006-7195)SL 5.x SRPMS:tomcat5-5.5.23-0jpp.1.0.4.el5.src.rpmjakarta-commons-modeler-1.1-8jpp.1.0.2.el5.src.rpm i386:jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.i386.rpmjakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.i386.rpmtomcat5-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-admin-webapps-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-common-lib-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-jasper-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-jasper-javadoc-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-jsp-2.0-api-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-server-lib-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-servlet-2.4-api-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.1.0.4.el5.i386.rpmtomcat5-webapps-5.5.23-0jpp.1.0.4.el5.i386.rpm x86_64:jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.x86_64.rpmjakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.x86_64.rpmtomcat5-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-admin-webapps-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-common-lib-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-jasper-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-jasper-javadoc-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-jsp-2.0-api-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-server-lib-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-servlet-2.4-api-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp.1.0.4.x86_64.rpmtomcat5-webapps-5.5.23-0jpp.1.0.4.x86_64.rpm-Connie Sieh-Troy Dawson