SCIENTIFIC-LINUX-ERRATA Archives

June 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Bonnie King <[log in to unmask]>
Reply To:
Date:
Thu, 20 Jun 2013 19:48:23 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (28 lines)
Synopsis:          Moderate: tomcat6 security update
Advisory ID:       SLSA-2013:0964-1
Issue Date:        2013-06-20
CVE Numbers:       CVE-2013-2067
--

A session fixation flaw was found in the Tomcat FormAuthenticator module.
During a narrow window of time, if a remote attacker sent requests while a
user was logging in, it could possibly result in the attacker's requests
being processed as if they were sent by the user. (CVE-2013-2067)

Tomcat must be restarted for this update to take effect.
--

SL6
  noarch
    tomcat6-6.0.24-57.el6_4.noarch.rpm
    tomcat6-admin-webapps-6.0.24-57.el6_4.noarch.rpm
    tomcat6-docs-webapp-6.0.24-57.el6_4.noarch.rpm
    tomcat6-el-2.1-api-6.0.24-57.el6_4.noarch.rpm
    tomcat6-javadoc-6.0.24-57.el6_4.noarch.rpm
    tomcat6-jsp-2.1-api-6.0.24-57.el6_4.noarch.rpm
    tomcat6-lib-6.0.24-57.el6_4.noarch.rpm
    tomcat6-servlet-2.5-api-6.0.24-57.el6_4.noarch.rpm
    tomcat6-webapps-6.0.24-57.el6_4.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2