Oval Definition:oval:org.mitre.oval:def:26374
Revision Date:2014-10-13Version:9
Title:RHSA-2014:1038: tomcat6 security update (Low)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServerPages (JSP) technologies.It was found that several application-provided XML files, such as web.xml,content.xml, *.tld, *.tagx, and *.jspx, resolved external entities,permitting XML External Entity (XXE) attacks. An attacker able to deploymalicious applications to Tomcat could use this flaw to circumvent securityrestrictions set by the JSM, and gain access to sensitive information onthe system. Note that this flaw only affected deployments in which Tomcatis running applications from untrusted sources, such as in a shared hostingenvironment. (CVE-2013-4590)It was found that, in certain circumstances, it was possible for amalicious web application to replace the XML parsers used by Apache Tomcatto process XSLTs for the default servlet, JSP documents, tag librarydescriptors (TLDs), and tag plug-in configuration files. The injected XMLparser(s) could then bypass the limits imposed on XML external entitiesand/or gain access to the XML files processed for other web applicationsdeployed on the same Apache Tomcat instance. (CVE-2014-0119)All Tomcat users are advised to upgrade to these updated packages, whichcontain backported patches to correct these issues. Tomcat must berestarted for this update to take effect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1038
CVE-2013-4590
CVE-2014-0119
RHSA-2014:1038-00
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):tomcat6
Definition Synopsis
  • Redhat 6 or Centos 6 release
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages section
  • tomcat6 is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-admin-webapps is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-docs-webapp is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-el-2.1-api is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-javadoc is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-jsp-2.1-api is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-lib is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-servlet-2.5-api is earlier than 0:6.0.24-78.el6_5
  • OR tomcat6-webapps is earlier than 0:6.0.24-78.el6_5
  • BACK