User: Password:
|
|
Subscribe / Log in / New account

Scientific Linux alert SL-tomc-20130620 (tomcat6)

From:  Bonnie King <bonniek@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Moderate: tomcat6 on SL6.x (noarch)
Date:  Thu, 20 Jun 2013 19:48:23 +0000
Message-ID:  <20130620194823.20460.55558@slpackages.fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: tomcat6 security update Advisory ID: SLSA-2013:0964-1 Issue Date: 2013-06-20 CVE Numbers: CVE-2013-2067 -- A session fixation flaw was found in the Tomcat FormAuthenticator module. During a narrow window of time, if a remote attacker sent requests while a user was logging in, it could possibly result in the attacker's requests being processed as if they were sent by the user. (CVE-2013-2067) Tomcat must be restarted for this update to take effect. -- SL6 noarch tomcat6-6.0.24-57.el6_4.noarch.rpm tomcat6-admin-webapps-6.0.24-57.el6_4.noarch.rpm tomcat6-docs-webapp-6.0.24-57.el6_4.noarch.rpm tomcat6-el-2.1-api-6.0.24-57.el6_4.noarch.rpm tomcat6-javadoc-6.0.24-57.el6_4.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-57.el6_4.noarch.rpm tomcat6-lib-6.0.24-57.el6_4.noarch.rpm tomcat6-servlet-2.5-api-6.0.24-57.el6_4.noarch.rpm tomcat6-webapps-6.0.24-57.el6_4.noarch.rpm - Scientific Linux Development Team


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds