First published: Fri May 03 2013(Updated: )
It was found that the fix for <a href="https://access.redhat.com/security/cve/CVE-2012-5887">CVE-2012-5887</a> shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Affected Software | Affected Version | How to fix |
---|---|---|
Tomcat | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-959047 is critical due to an incomplete fix for a security vulnerability.
REDHAT-BUG-959047 affects Red Hat Tomcat version 6.
To fix REDHAT-BUG-959047, you need to apply the latest patches provided by Red Hat for Tomcat 6.
REDHAT-BUG-959047 relates to the incomplete fix for CVE-2012-5887.
Currently, there are no recommended workarounds for REDHAT-BUG-959047; updating to the patched version is advised.