History | Log In     View a printable version of the current page. Get help!  
Issue Details (XML | Word)

Key: JBPAPP-302
Type: Bug Bug
Status: Resolved Resolved
Resolution: Done
Priority: Major Major
Assignee: Jean-Frederic Clere
Reporter: Takayoshi Kimura
Votes: 0
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
JBoss Enterprise Platform App Edition

Fix Tomcat security vulnerabilities, CVE-2007-3382 and CVE-2007-3385

Created: 20/Aug/07 08:58 PM   Updated: 28/Aug/07 12:04 AM
Component/s: App Server
Affects Version/s: 4.2.0.GA
Fix Version/s: 4.2.0.GA_CP01
Security Level: Public (Everyone can see)

Original Estimate: Unknown Remaining Estimate: Unknown Time Spent: Unknown
Issue Links:
Superset
 
This issue is incorporated by:
JBPAPP-317 Fix multiple potential vulnerabilitie... Blocker Closed

Affects: Release Notes


 Description  « Hide
We need to fix Tomcat security vulnerabilities, CVE-2007-3382 and CVE-2007-3385.

http://tomcat.apache.org/security-6.html


 All   Comments   Work Log   Change History   Subversion Commits      Sort Order:
Marc Schoenefeld [21/Aug/07 04:58 AM]
This issue is rated "LOW" by the Tomcat security team, it is fixed in version 6.0.14.
If possible tomcat 6 should be upgraded.

low: Session hi-jacking CVE-2007-3382

Tomcat incorrectly treated a single quote character (') in a cookie value as a delimiter. In some circumstances this lead to the leaking of information such as session ID to an attacker.

Affects: 6.0.0-6.0.13

low: Session hi-jacking CVE-2007-3385

Tomcat incorrectly handled the character sequence \" in a cookie value. In some circumstances this lead to the leaking of information such as session ID to an attacker.

Affects: 6.0.0-6.0.13

Fernando Nasser [21/Aug/07 10:13 AM]
Jean-Frederic, please feel free to re-assign to Remy or Mladen if that is the case.

Jean-Frederic Clere [23/Aug/07 05:10 PM]
Fixed.

Alex Pinkin [27/Aug/07 11:56 PM]
re-opening just to set Release Notes flag