CVE-2013-2051: Low severity red hat enterprise linux vulnerability
It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Other sources
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2051?
CVE-2013-2051 has a medium severity rating due to potential security implications in authentication processes.
How do I fix CVE-2013-2051?
To fix CVE-2013-2051, users should upgrade to a patched version of Tomcat provided by Red Hat for affected systems.
What systems are affected by CVE-2013-2051?
CVE-2013-2051 affects Red Hat Enterprise Linux 6.0 running Tomcat 6.
What is the nature of the vulnerability in CVE-2013-2051?
CVE-2013-2051 involves incomplete handling of DIGEST authentication, specifically concerning stale nonces.
When was CVE-2013-2051 discovered?
CVE-2013-2051 was published on October 16, 2013.