| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0191: Updated tomcat7 packages fix
CVE-2013-2071 |
| Date: |
| Mon, 1 Jul 2013 21:08:11 +0200 |
| Message-ID: |
| <20130701190811.45C5A41F97@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0191 - Updated tomcat7 packages fix CVE-2013-2071
Publication date: 01 Jul 2013
URL: http://advisories.mageia.org/MGASA-2013-0191.html
Type: security
Affected Mageia releases: 2, 3
CVE: CVE-2013-2071
Description:
java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x
before 7.0.40 does not properly handle the throwing of a RuntimeException
in an AsyncListener in an application, which allows context-dependent
attackers to obtain sensitive request information intended for other
applications in opportunistic circumstances via an application that records
the requests that it processes (CVE-2013-2071).
References:
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_...
- http://lists.fedoraproject.org/pipermail/package-announce...
- https://bugs.mageia.org/show_bug.cgi?id=10200
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2071
SRPMS:
- 3/core/tomcat-7.0.41-4.mga3
- 2/core/tomcat-7.0.41-3.mga2
(
Log in to post comments)