Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1403824 - (CVE-2016-8745) CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing
CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20161212,repo...
: Security
Depends On: 1403825 1413588 1413589 1413591 1413592 1424820 1470474
Blocks: 1403827 1428325
  Show dependency treegraph
 
Reported: 2016-12-12 07:42 EST by Martin Prpič
Modified: 2018-10-19 17:38 EDT (History)
79 users (show)

See Also:
Fixed In Version: tomcat 8.5.9, tomcat 9.0.0.M15, tomcat 6.0.50, tomcat 7.0.75, tomcat 8.0.41
Doc Type: If docs needed, set a value
Doc Text:
A bug was discovered in the error handling of the send file code for the NIO HTTP connector. This led to the current Processor object being added to the Processor cache multiple times allowing information leakage between requests including, and not limited to, session ID and the response body.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:0455 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 3.1.0 security and enhancement update 2017-03-07 19:06:40 EST
Red Hat Product Errata RHSA-2017:0456 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server 3.1.0 security and enhancement update 2017-03-07 19:06:06 EST
Red Hat Product Errata RHSA-2017:0457 normal SHIPPED_LIVE Important: Red Hat JBoss Web Server security and enhancement update 2017-03-07 19:05:59 EST
Red Hat Product Errata RHSA-2017:0527 normal SHIPPED_LIVE Moderate: tomcat6 security update 2017-03-15 13:01:42 EDT
Red Hat Product Errata RHSA-2017:0935 normal SHIPPED_LIVE Moderate: tomcat security update 2017-04-12 15:02:18 EDT

  None (edit)
Description Martin Prpič 2016-12-12 07:42:45 EST
The following flaw was found in Apache Tomcat:

A bug in the error handling of the send file code for the NIO HTTP connector resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent requests. Sharing a Processor can result in information leakage between requests including, not not limited to, session ID and the response body.

Upstream patch:
6.x: http://svn.apache.org/viewvc?view=revision&revision=1777472
7.x: http://svn.apache.org/viewvc?view=revision&revision=1777471
8.0.x: http://svn.apache.org/viewvc?view=revision&revision=1777469
8.5.x: https://svn.apache.org/viewvc?view=revision&revision=1771857
9.x: https://svn.apache.org/viewvc?view=revision&revision=1771853
Comment 1 Martin Prpič 2016-12-12 07:45:00 EST
Created tomcat tracking bugs for this issue:

Affects: fedora-all [bug 1403825]
Comment 7 Coty Sutherland 2017-02-17 15:33:40 EST
I've submitted an update for this on epel-6 already just a moment ago. I guess we should file a bug for it and add it to the update?
Comment 8 Martin Prpič 2017-02-19 11:49:40 EST
Created tomcat tracking bugs for this issue:

Affects: epel-6 [bug 1424820]
Comment 9 Martin Prpič 2017-02-19 11:50:42 EST
(In reply to Coty Sutherland from comment #7)
> I've submitted an update for this on epel-6 already just a moment ago. I
> guess we should file a bug for it and add it to the update?

Done, please use bug 1424820.
Comment 10 errata-xmlrpc 2017-03-07 14:11:20 EST
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 3.1.0

Via RHSA-2017:0457 https://rhn.redhat.com/errata/RHSA-2017-0457.html
Comment 11 errata-xmlrpc 2017-03-07 14:15:50 EST
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 3 for RHEL 7

Via RHSA-2017:0456 https://access.redhat.com/errata/RHSA-2017:0456
Comment 12 errata-xmlrpc 2017-03-07 14:20:21 EST
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 3 for RHEL 6

Via RHSA-2017:0455 https://access.redhat.com/errata/RHSA-2017:0455
Comment 13 errata-xmlrpc 2017-03-15 09:03:04 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:0527 https://rhn.redhat.com/errata/RHSA-2017-0527.html
Comment 14 errata-xmlrpc 2017-04-12 11:05:00 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0935 https://access.redhat.com/errata/RHSA-2017:0935
Comment 16 Kurt Seifried 2017-07-12 22:09:37 EDT
Created jbossweb tracking bugs for this issue:

Affects: openshift-1 [bug 1470474]

Note You need to log in before you can comment on or make changes to this bug.