Security Advisory tomcat security update for Stronghold

Advisory: RHSA-2002:217-03
Type: Security Advisory
Severity: Important
Issued on: 2002-11-08
Last updated on: 2002-10-01
Affected Products:
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-1148

Details

Updated tomcat packages are now available for Stronghold Cross Platform to
close a JSP source code exposure vulnerability.

Tomcat is the servlet container that is used in the official Reference
Implementation for the Java Servlet and JavaServer Pages technologies. A
source code exposure vulnerability has been found that affects Tomcat
versions 4.0.0 through 4.0.4 and 4.1.0 through 4.1.10.

Using a carefully crafted request, a remote attacker can read the source
code of any deployed JSP file.

Stronghold Cross Platform shipped with Tomcat version 4.0.3 and is
therefore susceptible to this vulnerability.

All users are advised to upgrade to these errata packages containing
Tomcat version 4.0.5 which is not vulnerable to this issue.


Solution

The updated packages are now available via the update agent service. Run
the command

$ bin/agent

from the Stronghold 4 install root to upgrade an existing Stronghold 4
installation to the new package versions. After upgrading Stronghold, the
server must be completely restarted by running the following commands from
the install root:

$ bin/stop-server
$ bin/stop-tomcat
$ bin/start-tomcat
$ bin/start-server

For more information on how to upgrade between releases of Stronghold 4,
see http://stronghold.redhat.com/support/upgrade-sh4

Updated packages


Bugs fixed (see bugzilla for more information)

71144 - Text files are DOS format
71167 - A reload-tomcat script would be handy
71175 - Examples in catalina.policy file are broken
71177 - Content-type not set for errors
73724 - Tomcat HTTP server DoS vulnerability


References


Keywords

code, exposure, JSP, source, tomcat


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/