Bug 428268 - CVE-2007-5333 Improve cookie parsing for tomcat5 [rhn_satellite_4.2]
CVE-2007-5333 Improve cookie parsing for tomcat5 [rhn_satellite_4.2]
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Other (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Miroslav Suchý
Preethi Thomas
: Security
Depends On:
Blocks: 135141 CVE-2007-5333 439866
  Show dependency treegraph
Reported: 2008-01-10 07:48 EST by Marc Schoenefeld
Modified: 2008-06-17 10:03 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-06-03 10:11:48 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Marc Schoenefeld 2008-01-10 07:48:42 EST
rhn_satellite_4.2 tracking bug: see blocks bug list for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes in the 'blocks' bugs.

For the security issues handling process overview see: http://intranet.corp.redhat.com/ic/intranet/SecurityZStreamFAQ

[bug automatically created by: add-tracking-bugs]
Comment 1 Miroslav Suchý 2008-04-16 08:00:19 EDT
Promoted tomcat5-5.0.30-0jpp_10rh.noarch.rpm from support-satellite-5.0-4AS-java
collection, where we fixed it.
Comment 2 Miroslav Suchý 2008-04-29 08:18:52 EDT
QA push for 4.2.3 complete: satellite-4.2.3-1 and proxy-4.2.3-1 are
now on webqa. Note that there is _no_ ISO planned for the 4.2.3

Developers, please move your bugs ON_QA.
Comment 3 Preethi Thomas 2008-05-07 14:01:49 EDT
verified in sat 4.2.3 rhel3 & rhel4  
Comment 4 Mark J. Cox 2008-06-02 05:25:34 EDT
Even if fix is included we won't claim to fix this CVE because of 

Comment 5 Miroslav Suchý 2008-06-03 10:11:48 EDT
WontFIX based on #4

Note You need to log in before you can comment on or make changes to this bug.