Bug 961803 - (CVE-2013-2071) CVE-2013-2071 tomcat: Information disclosure in asynchronous context when using AsyncListeners that threw RuntimeExceptions
CVE-2013-2071 tomcat: Information disclosure in asynchronous context when usi...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20130510,reported=2...
: Security
Depends On: 961806 962270
Blocks: 959037 961808
  Show dependency treegraph
 
Reported: 2013-05-10 08:34 EDT by Jan Lieskovsky
Modified: 2015-07-31 07:57 EDT (History)
9 users (show)

See Also:
Fixed In Version: Apache Tomcat 7.0.40
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-07-03 14:08:06 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2013-05-10 08:34:51 EDT
An information disclosure flaw was found in the way asynchronous context implementation of Apache Tomcat, an Apache Servlet/JSP Engine, performed request information management in certain circumstances (formerly certain elements of a previous request might have been exposed to the current request). If an application used AsyncListeners that threw RuntimeExceptions, a remote attacker could use this flaw to possibly obtain sensitive information.

Upstream bug report:
https://issues.apache.org/bugzilla/show_bug.cgi?id=54178

Relevant upstream patch (including testcase):
http://svn.apache.org/viewvc?view=rev&rev=1471372
Comment 1 Jan Lieskovsky 2013-05-10 09:02:20 EDT
This issue affects the versions of the tomcat package, as shipped with Fedora release of 17 and 18. Please schedule an update.

--

This issue did NOT affect the versions of the tomcat6 packages, as shipped with Fedora release of 17 and 18 (as those versions did not contain the vulnerable code part yet).
Comment 2 Jan Lieskovsky 2013-05-10 09:02:53 EDT
Created tomcat tracking bugs for this issue

Affects: fedora-all [bug 961806]
Comment 3 David Jorm 2013-05-13 00:26:35 EDT
Statement:

This flaw only affects tomcat 7. Tomcat 5 and 6 are not affected. The jbossweb servlet container is also not affected.
Comment 5 errata-xmlrpc 2013-07-03 11:49:59 EDT
This issue has been addressed in following products:

  JBEWS 2 for RHEL 6

Via RHSA-2013:1012 https://rhn.redhat.com/errata/RHSA-2013-1012.html
Comment 6 errata-xmlrpc 2013-07-03 11:51:51 EDT
This issue has been addressed in following products:

  JBEWS 2 for RHEL 5

Via RHSA-2013:1011 https://rhn.redhat.com/errata/RHSA-2013-1011.html
Comment 7 errata-xmlrpc 2013-07-03 12:22:56 EDT
This issue has been addressed in following products:

  Red Hat JBoss Web Server 2.0.1

Via RHSA-2013:1013 https://rhn.redhat.com/errata/RHSA-2013-1013.html

Note You need to log in before you can comment on or make changes to this bug.