[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[RedHat] Mehrere Schwachstellen in Apache Tomcat vor Version 6.0.14 - RHSA-2007:0876-01
-----BEGIN PGP SIGNED MESSAGE-----
Hash: MD5
Liebe Kolleginnen und Kollegen,
soeben erreichte uns nachfolgendes RedHat Security Advisory. Wir geben
diese Informationen unveraendert an Sie weiter.
CVE-2007-1358 - Cross-site Scripting Schwachstelle in Tomcat
Der Tomcat Application Server beinhaltet eine Cross-Site Scripting
Schwachstelle bei der Auswertung von 'Accept-Language' Headern. Ein
entferter Angreifer kann diese Schwachstelle ausnutzen um beliebige
Befehle im Webbrowser eines Opfers auszufuehren.
CVE-2007-2449 - Cross-Site Scripting Schwachstellen in Apache Tomcat
Beispielskripten
Mehrere mit Apache Tomcat gelieferten Beispielskripte lassen sich
aufgrund ungenuegender Filterung der Eingabedaten zu Cross-Site
Scripting Angriffen missbrauchen. Entfernte Angreifer koennen dadurch
Script Code im Browser anderer Benutzer ausfuehren.
CVE-2007-2450 - Cross-Site Scripting Schwachstellen in
Die Manager und Host Manager Anwendungen in Apache Tomcat filtern die
uebergebenen Daten u.a. im Parameter 'name' in den Skript upload
ungenuegend und koennen so fuer Cross-Site Scripting Angriffe
missbraucht werden. Entfernte Angreifer, die sich in der Anwendung
authentifiziert haben, koennen dadurch Script Code im Browser anderer
Benutzer ausfuehren.
CVE-2007-3382 - Quoting Fehler bzgl. einfacher Anfuehrungszeichen in
Cookies in Apache Tomcat
Apache Tomcat in den Versionen 6.0.0 - 6.0.13, 5.5.0 - 5.5.24, 5.0.0 -
5.0.30, 4.1.0 - 4.1.36 und 3.3 - 3.3.2 betrachtet einfache
Anfuehrungszeichen (') als Abschlusszeichen innerhalb von Cookies.
Dadurch kann evtl. vertrauliche Information an Angreifer gelangen, wie
z.B. Session IDs.
CVE-2007-3385 - Quoting Fehler bzgl. Backslashes in Cookies in Apache
Tomcat
Apache Tomcat in den Versionen 6.0.0 - 6.0.13, 5.5.0 - 5.5.24, 5.0.0 -
5.0.30, 4.1.0 - 4.1.36 und 3.3 - 3.3.2 verarbeitet die Sequenz \"
(Backslash gefolgt von einem doppelten Anfuehrungszeichen) innerhalb
von Cookies nicht korrekt. Dadurch kann evtl. vertrauliche Information
an Angreifer gelangen, wie z.B. Session IDs.
CVE-2007-3386 - Cross-site Scripting Schwachstelle im Apache Tomcat Host
Manager Servlet
Im Host Manager Servlet von Apache Tomcat befindet sich eine
Cross-site Scritping Schwachstelle. Dadurch koennen Angreifer
beliebigen HTML- oder Scriptcoder im Browser fremder Benutzer
ausfuehren.
Die Schwachstelle betrifft Apache Tomcat in den Versionen 6.0.0 -
6.0.13 und 5.5.0 - 5.5.24.
Betroffen sind die folgenden Software Pakete und Plattformen:
Paket tomcat
Red Hat Application Server v2 4AS - noarch
Red Hat Application Server v2 4ES - noarch
Red Hat Application Server v2 4WS - noarch
Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.
Hersteller Advisory:
https://rhn.redhat.com/errata/RHSA-2007-0876.html
(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.
Mit freundlichen Gruessen,
Jan Kohlrausch
- --
Jan Kohlrausch (CSIRT), Phone +49 40 808077-555
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-555
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Heidenkampsweg 41, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - ---------------------------------------------------------------------
Red Hat Security Advisory
Synopsis: Moderate: tomcat security update
Advisory ID: RHSA-2007:0876-01
Advisory URL: https://rhn.redhat.com/errata/RHSA-2007-0876.html
Issue date: 2007-10-11
Updated on: 2007-10-11
Product: Red Hat Application Server
CVE Names: CVE-2007-1358 CVE-2007-2449 CVE-2007-2450
CVE-2007-3382 CVE-2007-3385 CVE-2007-3386
- - ---------------------------------------------------------------------
1. Summary:
Updated tomcat packages that fix multiple security issues are now available
for Red Hat Application Server v2.
This update has been rated as having moderate security impact by the Red
Hat Security Response Team.
2. Relevant releases/architectures:
Red Hat Application Server v2 4AS - noarch
Red Hat Application Server v2 4ES - noarch
Red Hat Application Server v2 4WS - noarch
3. Problem description:
Tomcat is a servlet container for Java Servlet and Java Server Pages
technologies.
Tomcat incorrectly handled "Accept-Language" headers that do not conform to
RFC 2616. An attacker was able to perform cross-site scripting (XSS)
attacks in certain applications (CVE-2007-1358).
Some JSPs within the 'examples' web application did not escape user
provided data. If the JSP examples were accessible, this flaw could allow a
remote attacker to perform cross-site scripting attacks (CVE-2007-2449).
Note: it is recommended the 'examples' web application not be installed on
a production system.
The Manager and Host Manager web applications did not escape user provided
data. If a user is logged in to the Manager or Host Manager web
application, an attacker could perform a cross-site scripting attack
(CVE-2007-2450).
Tomcat was found treating single quote characters -- ' -- as delimiters in
cookies. This could allow remote attackers to obtain sensitive information,
such as session IDs, for session hijacking attacks (CVE-2007-3382).
It was reported Tomcat did not properly handle the following character
sequence in a cookie: \" (a backslash followed by a double-quote). It was
possible remote attackers could use this failure to obtain sensitive
information, such as session IDs, for session hijacking attacks
(CVE-2007-3385).
A cross-site scripting (XSS) vulnerability existed in the Host Manager
Servlet. This allowed remote attackers to inject arbitrary HTML and web
script via crafted requests (CVE-2007-3386).
Users of Tomcat should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.
4. Solution:
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188
5. Bug IDs fixed (http://bugzilla.redhat.com/):
244803 - CVE-2007-1358 tomcat accept-language xss flaw
244804 - CVE-2007-2449 tomcat examples jsp XSS
244808 - CVE-2007-2450 tomcat host manager XSS
247972 - CVE-2007-3382 tomcat handling of cookies
247976 - CVE-2007-3385 tomcat handling of cookie values
247994 - CVE-2007-3386 tomcat host manager xss
6. RPMs required:
Red Hat Application Server v2 4AS:
SRPMS:
ftp://updates.redhat.com/enterprise/4AS/en/RHAPS/SRPMS/tomcat5-5.5.23-0jpp_4rh.4.src.rpm
c8a9674009457794d5969b0a4db09888 tomcat5-5.5.23-0jpp_4rh.4.src.rpm
noarch:
92c991a50808cc48ff7538e3320cd146 tomcat5-5.5.23-0jpp_4rh.4.noarch.rpm
364a741ad7d232a9fe1cf3e183001520 tomcat5-admin-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
c7afc607c579c4db42bcc094df7b5498 tomcat5-common-lib-5.5.23-0jpp_4rh.4.noarch.rpm
044ec1d57f92903b32c4dd3f97211ea4 tomcat5-jasper-5.5.23-0jpp_4rh.4.noarch.rpm
2790253849bae9be0960517cfd781c4c tomcat5-jasper-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
0d64bdd04f35659f0b425843bf4cfda2 tomcat5-jsp-2.0-api-5.5.23-0jpp_4rh.4.noarch.rpm
7b8448505ae5e74010fa8fb37084dd6e tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
3397d6f2b3ed49fcaa5616fb3363c0ce tomcat5-server-lib-5.5.23-0jpp_4rh.4.noarch.rpm
8f28858bc131b40e9effdac8f0d445ad tomcat5-servlet-2.4-api-5.5.23-0jpp_4rh.4.noarch.rpm
0ea67bc6674bbc1e6fc50809a6594d9b tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
6ca13028e1547f3630aefcfd73a84424 tomcat5-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
Red Hat Application Server v2 4ES:
SRPMS:
ftp://updates.redhat.com/enterprise/4ES/en/RHAPS/SRPMS/tomcat5-5.5.23-0jpp_4rh.4.src.rpm
c8a9674009457794d5969b0a4db09888 tomcat5-5.5.23-0jpp_4rh.4.src.rpm
noarch:
92c991a50808cc48ff7538e3320cd146 tomcat5-5.5.23-0jpp_4rh.4.noarch.rpm
364a741ad7d232a9fe1cf3e183001520 tomcat5-admin-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
c7afc607c579c4db42bcc094df7b5498 tomcat5-common-lib-5.5.23-0jpp_4rh.4.noarch.rpm
044ec1d57f92903b32c4dd3f97211ea4 tomcat5-jasper-5.5.23-0jpp_4rh.4.noarch.rpm
2790253849bae9be0960517cfd781c4c tomcat5-jasper-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
0d64bdd04f35659f0b425843bf4cfda2 tomcat5-jsp-2.0-api-5.5.23-0jpp_4rh.4.noarch.rpm
7b8448505ae5e74010fa8fb37084dd6e tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
3397d6f2b3ed49fcaa5616fb3363c0ce tomcat5-server-lib-5.5.23-0jpp_4rh.4.noarch.rpm
8f28858bc131b40e9effdac8f0d445ad tomcat5-servlet-2.4-api-5.5.23-0jpp_4rh.4.noarch.rpm
0ea67bc6674bbc1e6fc50809a6594d9b tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
6ca13028e1547f3630aefcfd73a84424 tomcat5-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
Red Hat Application Server v2 4WS:
SRPMS:
ftp://updates.redhat.com/enterprise/4WS/en/RHAPS/SRPMS/tomcat5-5.5.23-0jpp_4rh.4.src.rpm
c8a9674009457794d5969b0a4db09888 tomcat5-5.5.23-0jpp_4rh.4.src.rpm
noarch:
92c991a50808cc48ff7538e3320cd146 tomcat5-5.5.23-0jpp_4rh.4.noarch.rpm
364a741ad7d232a9fe1cf3e183001520 tomcat5-admin-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
c7afc607c579c4db42bcc094df7b5498 tomcat5-common-lib-5.5.23-0jpp_4rh.4.noarch.rpm
044ec1d57f92903b32c4dd3f97211ea4 tomcat5-jasper-5.5.23-0jpp_4rh.4.noarch.rpm
2790253849bae9be0960517cfd781c4c tomcat5-jasper-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
0d64bdd04f35659f0b425843bf4cfda2 tomcat5-jsp-2.0-api-5.5.23-0jpp_4rh.4.noarch.rpm
7b8448505ae5e74010fa8fb37084dd6e tomcat5-jsp-2.0-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
3397d6f2b3ed49fcaa5616fb3363c0ce tomcat5-server-lib-5.5.23-0jpp_4rh.4.noarch.rpm
8f28858bc131b40e9effdac8f0d445ad tomcat5-servlet-2.4-api-5.5.23-0jpp_4rh.4.noarch.rpm
0ea67bc6674bbc1e6fc50809a6594d9b tomcat5-servlet-2.4-api-javadoc-5.5.23-0jpp_4rh.4.noarch.rpm
6ca13028e1547f3630aefcfd73a84424 tomcat5-webapps-5.5.23-0jpp_4rh.4.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package
7. References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1358
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2449
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2450
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3382
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3385
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3386
http://tomcat.apache.org/security-5.html
http://www.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@xxxxxxxxxx>. More contact
details at https://www.redhat.com/security/team/contact/
Copyright 2007 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
iD8DBQFHDmrOXlSAg2UNWIIRAl3OAJ0QBkIqF754UEPVQFJ7Gr+1CcBOfQCgp7iW
aIwNdS1PiHUTzjC3Yd+l+IM=
=AQ6M
- -----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
iQEVAwUBRw9VLxYd1iQZmhQQAQGa+AgAogcvLwIsxhJQataZQOnCgRlZcBL0rrd8
nhnuxhWUsRSz1y4efaWW94tr8wIl0vWNzlnXOyeGyNinXUUYKkYObpLDzEJzf3pB
Gb34bGkK5tIEylzHZWi959mdyUZjJUh/tnM+Bj2eVEYZbAc/TY5ggT4AlmycqcZ3
XG0kubuFYdu/KKPlYctlNM42zBziUNZtm4lHri6nRmYkw+jto0c2Vn1AiaGIoO6B
9eiiZQ0Nx/I4ARA8hmSlf8Bk7f1qKay3yWNMA6DAybMesH8VyG4ehdUHevzVDRVu
2vsJgIskTf17z5Q59MVwrIcIqJ0h+0ttP1WiZN0VWpCJbz8EhgPSHg==
=ckdD
-----END PGP SIGNATURE-----