RHSA-2007:1069: Moderate: tomcat security update for Red Hat Network Satellite Server

Published Nov 26, 2007
·
Updated

Tomcat is a servlet container for Java Servlet and JavaServer Pagestechnologies.It was reported Tomcat did not properly handle the following charactersequence in a cookie: \" (a backslash followed by a double-quote). It waspossible remote attackers could use this failure to obtain sensitiveinformation, such as session IDs, for session hijacking attacks(CVE-2007-3385). Tomcat was found treating single quote characters -- ' -- as delimiters incookies. This could allow remote attackers to obtain sensitive information,such as session IDs, for session hijacking attacks (CVE-2007-3382).The default Tomcat configuration permitted the use of insecureSSL cipher suites including the anonymous cipher suite. (CVE-2007-1858)Tomcat permitted various characters as path delimiters. If Tomcat was usedbehind certain proxies and configured to only proxy some contexts, anattacker could construct an HTTP request to work around the contextrestriction and potentially access non-proxied content. (CVE-2007-0450)Directory listings were enabled by default in Tomcat. Information storedunprotected under the document root was visible to anyone if theadministrator did not disable directory listings. (CVE-2006-3835)It was found that generating listings of large directories was CPUintensive. An attacker could make repeated requests to obtain a directorylisting of any large directory, leading to a denial of service.(CVE-2005-3510) Tomcat was found to accept multiple content-length headers in arequest. This could allow attackers to poison a web-cache, bypass webapplication firewall protection, or conduct cross-site scripting attacks.(CVE-2005-2090)Users should upgrade to these erratum packages which contain an update toTomcat that resolves these issues, and add the tyrex andjakarta-commons-pool packages which are required dependencies of the newTomcat version.

Affected Software

2 affected components
Red Hat Network Satellite Server
Apache Tomcat

Remediation

Event History

Nov 26, 2007
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2007:1069?

The severity of RHSA-2007:1069 is classified as important due to potential remote code execution.

2

How do I fix RHSA-2007:1069?

To fix RHSA-2007:1069, update Tomcat to the latest version as specified in the security advisory.

3

What vulnerabilities are addressed by RHSA-2007:1069?

RHSA-2007:1069 addresses the improper handling of special characters in cookies, which could lead to security issues.

4

Which versions of Tomcat are affected by RHSA-2007:1069?

RHSA-2007:1069 affects specific versions of Tomcat prior to the security update.

5

Is remote access required to exploit RHSA-2007:1069?

Yes, remote access is required for an attacker to exploit the vulnerability addressed in RHSA-2007:1069.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203