RHSA-2008:0648: Important: tomcat security update
Apache Tomcat is a servlet container for the Java Servlet and JavaServerPages (JSP) technologies.A cross-site scripting vulnerability was discovered in theHttpServletResponse.sendError() method. A remote attacker could injectarbitrary web script or HTML via forged HTTP headers. (CVE-2008-1232)An additional cross-site scripting vulnerability was discovered in the hostmanager application. A remote attacker could inject arbitrary web script orHTML via the hostname parameter. (CVE-2008-1947)A traversal vulnerability was discovered when using a RequestDispatcherin combination with a servlet or JSP. A remote attacker could utilize aspecially-crafted request parameter to access protected web resources.(CVE-2008-2370)An additional traversal vulnerability was discovered when the"allowLinking" and "URIencoding" settings were activated. A remote attackercould use a UTF-8-encoded request to extend their privileges and obtainlocal files accessible to the Tomcat process. (CVE-2008-2938)Users of tomcat should upgrade to these updated packages, which containbackported patches to resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0648?
The severity of RHSA-2008:0648 is classified as moderate due to a cross-site scripting vulnerability.
How do I fix RHSA-2008:0648?
To fix RHSA-2008:0648, upgrade to the corrective version 5.5.23-0jpp.7.el5_2.1 or later.
What systems are affected by RHSA-2008:0648?
RHSA-2008:0648 affects systems running Apache Tomcat versions prior to 5.5.23-0jpp.7.el5_2.1.
What type of vulnerability is described in RHSA-2008:0648?
RHSA-2008:0648 describes a cross-site scripting vulnerability that allows injection of arbitrary web scripts.
Can a remote attacker exploit RHSA-2008:0648?
Yes, a remote attacker could exploit RHSA-2008:0648 to execute arbitrary scripts on the victim's browser.