Skip to navigation

Security Advisory Important: tomcat security update

Advisory: RHSA-2007:0328-2
Type: Security Advisory
Severity: Important
Issued on: 2007-05-24
Last updated on: 2007-05-24
Affected Products: Developer Suite v3 EL4
CVEs (cve.mitre.org): CVE-2005-2090
CVE-2006-7195
CVE-2007-0450
CVE-2007-1358

Details

Updated tomcat packages that fix multiple security issues and a bug are now
available for Red Hat Developer Suite 3.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

Tomcat is a servlet container for Java Servlet and JavaServer Pages
technologies.

Tomcat was found to accept multiple content-length headers in a
request. This could allow attackers to poison a web-cache, bypass web
application firewall protection, or conduct cross-site scripting attacks.
(CVE-2005-2090)

Tomcat permitted various characters as path delimiters. If Tomcat was used
behind certain proxies and configured to only proxy some contexts, an
attacker could construct an HTTP request to work around the context
restriction and potentially access non-proxied content. (CVE-2007-0450)

The implict-objects.jsp file distributed in the examples webapp displayed a
number of unfiltered header values. If the JSP examples are accessible,
this flaw could allow a remote attacker to perform cross-site scripting
attacks. (CVE-2006-7195)

Updated jakarta-commons-modeler packages which correct a bug when
used with Tomcat 5.5.23 are also included.

Users should upgrade to these erratum packages which contain an update to
Tomcat that resolves these issues.


Solution

Note: /etc/tomcat5/web.xml has been updated to disable directory listing by
default. If you have previously modified /etc/tomcat5/web.xml, this change
will not be made automatically and you should manually update the value for
the "listings" parameter to "false".

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Developer Suite v3 EL4

SRPMS:
jakarta-commons-modeler-2.0-3jpp_3rh.src.rpm     MD5: 4222be2605c1611c0fa35dbb6bd6e4f0
 
IA-32:
jakarta-commons-modeler-2.0-3jpp_3rh.noarch.rpm     MD5: 9390a4076d922b0de9560187e83a6f82
tomcat5-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: a65422af787444bc997f561246e94348
tomcat5-common-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: bfac8a20f267cf60b508bd3097827d3f
tomcat5-jasper-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 612d61b93903cfff32be17dc7faa733b
tomcat5-jsp-2.0-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 6ad168cda6379b7c6c0348eb1fc6a52e
tomcat5-server-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 41b2143aafc7986f8d7ae7b84eca9411
tomcat5-servlet-2.4-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: cf311e6fc560319b3581e6a1b80c81a6
 
IA-64:
jakarta-commons-modeler-2.0-3jpp_3rh.noarch.rpm     MD5: 9390a4076d922b0de9560187e83a6f82
tomcat5-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: a65422af787444bc997f561246e94348
tomcat5-common-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: bfac8a20f267cf60b508bd3097827d3f
tomcat5-jasper-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 612d61b93903cfff32be17dc7faa733b
tomcat5-jsp-2.0-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 6ad168cda6379b7c6c0348eb1fc6a52e
tomcat5-server-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 41b2143aafc7986f8d7ae7b84eca9411
tomcat5-servlet-2.4-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: cf311e6fc560319b3581e6a1b80c81a6
 
PPC:
jakarta-commons-modeler-2.0-3jpp_3rh.noarch.rpm     MD5: 9390a4076d922b0de9560187e83a6f82
tomcat5-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: a65422af787444bc997f561246e94348
tomcat5-common-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: bfac8a20f267cf60b508bd3097827d3f
tomcat5-jasper-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 612d61b93903cfff32be17dc7faa733b
tomcat5-jsp-2.0-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 6ad168cda6379b7c6c0348eb1fc6a52e
tomcat5-server-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 41b2143aafc7986f8d7ae7b84eca9411
tomcat5-servlet-2.4-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: cf311e6fc560319b3581e6a1b80c81a6
 
x86_64:
jakarta-commons-modeler-2.0-3jpp_3rh.noarch.rpm     MD5: 9390a4076d922b0de9560187e83a6f82
tomcat5-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: a65422af787444bc997f561246e94348
tomcat5-common-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: bfac8a20f267cf60b508bd3097827d3f
tomcat5-jasper-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 612d61b93903cfff32be17dc7faa733b
tomcat5-jsp-2.0-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 6ad168cda6379b7c6c0348eb1fc6a52e
tomcat5-server-lib-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: 41b2143aafc7986f8d7ae7b84eca9411
tomcat5-servlet-2.4-api-5.5.23-0jpp_6rh.noarch.rpm
File outdated by:  RHSA-2010:0583
    MD5: cf311e6fc560319b3581e6a1b80c81a6
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

237109 - CVE-2005-2090 multiple tomcat issues (CVE-2007-0450 CVE-2006-7195)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/