An information disclosure flaw was found in the way asynchronous context implementation of Apache Tomcat, an Apache Servlet/JSP Engine, performed request information management in certain circumstances (formerly certain elements of a previous request might have been exposed to the current request). If an application used AsyncListeners that threw RuntimeExceptions, a remote attacker could use this flaw to possibly obtain sensitive information.
Upstream bug report:
https://issues.apache.org/bugzilla/show_bug.cgi?id=54178
Relevant upstream patch (including testcase):
http://svn.apache.org/viewvc?view=rev&rev=1471372
This issue affects the versions of the tomcat package, as shipped with Fedora release of 17 and 18. Please schedule an update.
--
This issue did NOT affect the versions of the tomcat6 packages, as shipped with Fedora release of 17 and 18 (as those versions did not contain the vulnerable code part yet).