Oval Definition:oval:com.redhat.rhsa:def:20130869
Revision Date:2013-05-28Version:644
Title:RHSA-2013:0869: tomcat6 security update (Important)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.

  • A flaw was found in the way the tomcat6 init script handled the tomcat6-initd.log log file. A malicious web application deployed on Tomcat could use this flaw to perform a symbolic link attack to change the ownership of an arbitrary system file to that of the tomcat user, allowing them to escalate their privileges to root. (CVE-2013-1976)

    Note: With this update, tomcat6-initd.log has been moved from /var/log/tomcat6/ to the /var/log/ directory.

  • It was found that the RHSA-2013:0623 update did not correctly fix CVE-2012-5887, a weakness in the Tomcat DIGEST authentication implementation. A remote attacker could use this flaw to perform replay attacks in some circumstances. Additionally, this problem also prevented users from being able to authenticate using DIGEST authentication. (CVE-2013-2051)

    Red Hat would like to thank Simon Fayer of Imperial College London for reporting the CVE-2013-1976 issue.

    Users of Tomcat are advised to upgrade to these updated packages, which correct these issues. Tomcat must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-1976
    CVE-2013-1976
    CVE-2013-2051
    CVE-2013-2051
    RHSA-2013:0869
    RHSA-2013:0869-01
    RHSA-2013:0869-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • tomcat6 is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6 is signed with Red Hat redhatrelease2 key
  • tomcat6-admin-webapps is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-admin-webapps is signed with Red Hat redhatrelease2 key
  • tomcat6-docs-webapp is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-docs-webapp is signed with Red Hat redhatrelease2 key
  • tomcat6-el-2.1-api is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-el-2.1-api is signed with Red Hat redhatrelease2 key
  • tomcat6-javadoc is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-javadoc is signed with Red Hat redhatrelease2 key
  • tomcat6-jsp-2.1-api is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-jsp-2.1-api is signed with Red Hat redhatrelease2 key
  • tomcat6-lib is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-lib is signed with Red Hat redhatrelease2 key
  • tomcat6-servlet-2.5-api is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-servlet-2.5-api is signed with Red Hat redhatrelease2 key
  • tomcat6-webapps is earlier than 0:6.0.24-55.el6_4
  • AND tomcat6-webapps is signed with Red Hat redhatrelease2 key
  • BACK