LWN.net Logo

tomcat: information disclosure

Package(s):tomcat CVE #(s):CVE-2013-2071
Created:May 21, 2013 Updated:July 2, 2013
Description: From the Red Hat bugzilla:

An information disclosure flaw was found in the way asynchronous context implementation of Apache Tomcat, an Apache Servlet/JSP Engine, performed request information management in certain circumstances (formerly certain elements of a previous request might have been exposed to the current request). If an application used AsyncListeners that threw RuntimeExceptions, a remote attacker could use this flaw to possibly obtain sensitive information.

Alerts:
Fedora FEDORA-2013-7993 2013-05-21
Fedora FEDORA-2013-7999 2013-05-21
Ubuntu USN-1841-1 2013-05-28
Mageia MGASA-2013-0191 2013-07-01
openSUSE openSUSE-SU-2013:1306-1 2013-08-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds