Skip to navigation

Security Advisory Moderate: tomcat6 security and bug fix update

Advisory: RHSA-2011:1780-1
Type: Security Advisory
Severity: Moderate
Issued on: 2011-12-05
Last updated on: 2011-12-05
Affected Products: Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux HPC Node (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server EUS (v. 6.1.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2011-1184
CVE-2011-2204
CVE-2011-2526
CVE-2011-3190
CVE-2011-5062
CVE-2011-5063
CVE-2011-5064

Details

Updated tomcat6 packages that fix several security issues and one bug are
now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

APR (Apache Portable Runtime) as mentioned in the CVE-2011-3190 and
CVE-2011-2526 descriptions does not refer to APR provided by the apr
packages. It refers to the implementation of APR provided by the Tomcat
Native library, which provides support for using APR with Tomcat. This
library is not shipped with Red Hat Enterprise Linux 6. This update
includes fixes for users who have elected to use APR with Tomcat by taking
the Tomcat Native library from a different product. Such a configuration is
not supported by Red Hat, however.

Multiple flaws were found in the way Tomcat handled HTTP DIGEST
authentication. These flaws weakened the Tomcat HTTP DIGEST authentication
implementation, subjecting it to some of the weaknesses of HTTP BASIC
authentication, for example, allowing remote attackers to perform session
replay attacks. (CVE-2011-1184)

A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor)
and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ
Protocol) connectors processed certain POST requests. An attacker could
send a specially-crafted request that would cause the connector to treat
the message body as a new request. This allows arbitrary AJP messages to be
injected, possibly allowing an attacker to bypass a web application's
authentication checks and gain access to information they would otherwise
be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler)
connector is used by default when the APR libraries are not present. The JK
connector is not affected by this flaw. (CVE-2011-3190)

A flaw was found in the Tomcat MemoryUserDatabase. If a runtime exception
occurred when creating a new user with a JMX client, that user's password
was logged to Tomcat log files. Note: By default, only administrators have
access to such log files. (CVE-2011-2204)

A flaw was found in the way Tomcat handled sendfile request attributes when
using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web
application running on a Tomcat instance could use this flaw to bypass
security manager restrictions and gain access to files it would otherwise
be unable to access, or possibly terminate the Java Virtual Machine (JVM).
The HTTP blocking IO (BIO) connector, which is not vulnerable to this
issue, is used by default in Red Hat Enterprise Linux 6. (CVE-2011-2526)

Red Hat would like to thank the Apache Tomcat project for reporting the
CVE-2011-2526 issue.

This update also fixes the following bug:

* Previously, in certain cases, if "LANG=fr_FR" or "LANG=fr_FR.UTF-8" was
set as an environment variable or in "/etc/sysconfig/tomcat6" on 64-bit
PowerPC systems, Tomcat may have failed to start correctly. With this
update, Tomcat works as expected when LANG is set to "fr_FR" or
"fr_FR.UTF-8". (BZ#748807)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to correct these issues. Tomcat must be restarted for
this update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

Updated packages

Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
tomcat6-6.0.24-35.el6_1.src.rpm
File outdated by:  RHBA-2013:1721
    MD5: ed0de7bbb58011b699c84ffb9228542b
SHA-256: d2679147192b038cd187ed1533a8569221915dc342b921479e07275d682bb6b9
 
IA-32:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
x86_64:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
Red Hat Enterprise Linux HPC Node (v. 6)

SRPMS:
tomcat6-6.0.24-35.el6_1.src.rpm
File outdated by:  RHBA-2013:1721
    MD5: ed0de7bbb58011b699c84ffb9228542b
SHA-256: d2679147192b038cd187ed1533a8569221915dc342b921479e07275d682bb6b9
 
x86_64:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
tomcat6-6.0.24-35.el6_1.src.rpm
File outdated by:  RHBA-2013:1721
    MD5: ed0de7bbb58011b699c84ffb9228542b
SHA-256: d2679147192b038cd187ed1533a8569221915dc342b921479e07275d682bb6b9
 
IA-32:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
PPC:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
s390x:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
x86_64:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
Red Hat Enterprise Linux Server EUS (v. 6.1.z)

SRPMS:
tomcat6-6.0.24-35.el6_1.src.rpm
File outdated by:  RHBA-2013:1721
    MD5: ed0de7bbb58011b699c84ffb9228542b
SHA-256: d2679147192b038cd187ed1533a8569221915dc342b921479e07275d682bb6b9
 
IA-32:
tomcat6-6.0.24-35.el6_1.noarch.rpm     MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm     MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm     MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm     MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm     MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
PPC:
tomcat6-6.0.24-35.el6_1.noarch.rpm     MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm     MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm     MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm     MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm     MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
s390x:
tomcat6-6.0.24-35.el6_1.noarch.rpm     MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm     MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm     MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm     MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm     MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
x86_64:
tomcat6-6.0.24-35.el6_1.noarch.rpm     MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm     MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm     MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm     MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm     MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm     MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm     MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
tomcat6-6.0.24-35.el6_1.src.rpm
File outdated by:  RHBA-2013:1721
    MD5: ed0de7bbb58011b699c84ffb9228542b
SHA-256: d2679147192b038cd187ed1533a8569221915dc342b921479e07275d682bb6b9
 
IA-32:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
x86_64:
tomcat6-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 4f8a16dc33d06e5c1eef75a8e379ea89
SHA-256: 527d040303db9353bcab2073af8ce01a76947699c0f4b527c013e77ce8951d17
tomcat6-admin-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 1e53209d6fe641c39d2536144af7478a
SHA-256: 49576b28c08061570c6e7efaa2a8828f29133010703e198eb67c55ccb3d6b062
tomcat6-docs-webapp-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: a8a64e27a054fc91dc251e4637c4e814
SHA-256: c4ad1c30ab306fd7bc7d617a67efb3550b7e386ef3ea6f24166094b2ee3a7538
tomcat6-el-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d6f3abfe130f444b985535152194722
SHA-256: 8c287793499b667ddacf53bccd6b66af79be0ac800ae11eb2ae9b235571db81a
tomcat6-javadoc-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 6926b5776ff05c485d187b107b9e797b
SHA-256: 7a9dbabb0c91fc53040aaa96f8679e0495d06bb9d3ad41bced22272d67cabfc5
tomcat6-jsp-2.1-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 702eb839537a1a2d04f3f0fc9a6f644c
SHA-256: 8c75ab74fa62579b8e7649676d39720ef2301a0a17280e151eb2c6a037e6a843
tomcat6-lib-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 7d87e04bfa94154c81e4f4c748c56943
SHA-256: 6fe8eb15923d298d8efcda287bee5c021c864d1dd6e86577d3d0c92adef6dcfc
tomcat6-servlet-2.5-api-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: 78fa95be0653b403a99ecf23779959d6
SHA-256: f7d87fa7c98959492c007be4c58fa7e3788e133767f0eb93f82a37c52ef182ea
tomcat6-webapps-6.0.24-35.el6_1.noarch.rpm
File outdated by:  RHBA-2013:1721
    MD5: df74c443e9440d9d193d3c4c3f1bad33
SHA-256: f8630ba995fb428ee421b7040c0865ac465eea7be95172001c44d206c06bf3ce
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

717013 - CVE-2011-2204 tomcat: password disclosure vulnerability
720948 - CVE-2011-2526 tomcat: security manager restrictions bypass
734868 - CVE-2011-3190 tomcat: authentication bypass and information disclosure
741401 - CVE-2011-1184 tomcat: Multiple weaknesses in HTTP DIGEST authentication


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/