Oval Definition:oval:com.redhat.rhsa:def:20080042
Revision Date:2008-03-11Version:637
Title:RHSA-2008:0042: tomcat security update (Moderate)
Description:Tomcat is a servlet container for Java Servlet and JavaServer Pages technologies.

  • A directory traversal vulnerability existed in the Apache Tomcat webdav servlet. In some configurations it allowed remote authenticated users to read files accessible to the local tomcat process. (CVE-2007-5461)

  • The default security policy in the JULI logging component did not restrict access permissions to files. This could be misused by untrusted web applications to access and write arbitrary files in the context of the tomcat process. (CVE-2007-5342)

    Users of Tomcat should update to these errata packages, which contain backported patches and are not vulnerable to these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-5342
    CVE-2007-5461
    RHSA-2008:0042
    RHSA-2008:0042-01
    RHSA-2008:0042-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • tomcat5 is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5 is signed with Red Hat redhatrelease2 key
  • tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-admin-webapps is signed with Red Hat redhatrelease2 key
  • tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-common-lib is signed with Red Hat redhatrelease2 key
  • tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-jasper is signed with Red Hat redhatrelease2 key
  • tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-jasper-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease2 key
  • tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-server-lib is signed with Red Hat redhatrelease2 key
  • tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease2 key
  • tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1
  • AND tomcat5-webapps is signed with Red Hat redhatrelease2 key
  • BACK