Bug 456120 (CVE-2008-2938)

Summary: CVE-2008-2938 tomcat Unicode directory traversal vulnerability
Product: [Other] Security Response Reporter: Marc Schoenefeld <mschoene>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dbhole, djorm, dwalluck
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-07-03 06:47:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 456214, 456216, 460125, 460126, 460127, 460131, 460132, 460177, 460646, 460647, 466471, 466472, 466473, 470243, 470244    
Bug Blocks:    
Attachments:
Description Flags
Patch for Tomcat 5.5.23 none

Description Marc Schoenefeld 2008-07-21 16:29:01 UTC
Tomcat allows remote attackers to access local resources via directory
traversal, iff the following two modifications have been applied
- URIEncoding in server.xml (tag Connector) is set to "UTF-8" 
- allowLinking in context.xml (tag Context) is set to "true"

Comment 13 Fedora Update System 2008-09-05 17:10:40 UTC
tomcat6-6.0.18-1.1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/tomcat6-6.0.18-1.1.fc9

Comment 14 Fedora Update System 2008-09-11 17:17:08 UTC
tomcat6-6.0.18-1.1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 Fedora Update System 2008-09-15 18:12:21 UTC
tomcat5-5.5.27-0jpp.1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/tomcat5-5.5.27-0jpp.1.fc8

Comment 16 Fedora Update System 2008-09-15 20:13:58 UTC
tomcat5-5.5.27-0jpp.2.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/tomcat5-5.5.27-0jpp.2.fc9

Comment 17 Fedora Update System 2008-09-15 20:16:30 UTC
tomcat5-5.5.27-0jpp.2.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/tomcat5-5.5.27-0jpp.2.fc8

Comment 18 Fedora Update System 2008-09-16 23:25:01 UTC
tomcat5-5.5.27-0jpp.2.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 19 Fedora Update System 2008-09-16 23:28:26 UTC
tomcat5-5.5.27-0jpp.2.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.