Oval Definition:oval:org.mitre.oval:def:7601
Revision Date:2014-06-23Version:17
Title:DSA-1468 tomcat5.5 -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in the Tomcat servlet and JSP engine. The Common Vulnerabilities and Exposures project identifies the following problems: Olaf Kock discovered that HTTPS encryption was insufficiently enforced for single-sign-on cookies, which could result in information disclosure. It was discovered that the Manager and Host Manager web applications performed insufficient input sanitising, which could lead to cross site scripting. This update also adapts the tomcat5.5-webapps package to the tightened JULI permissions introduced in the previous tomcat5.5 DSA. However, it should be noted, that the tomcat5.5-webapps is for demonstration and documentation purposes only and should not be used for production systems. The old stable distribution (sarge) doesn't contain tomcat5.5.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-2450
CVE-2008-0128
DSA-1468
Platform(s):Debian GNU/Linux 4.0
Product(s):tomcat5.5
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND Packages section
  • libtomcat5.5-java is earlier than 5.5.20-2etch2
  • OR tomcat5.5-admin is earlier than 5.5.20-2etch2
  • OR tomcat5.5-webapps is earlier than 5.5.20-2etch2
  • OR tomcat5.5 is earlier than 5.5.20-2etch2
  • BACK