Vulnerability Bulletins |
Múltiples cross-site scripting en Tomcat |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Integridad |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | GNU/Linux |
| Affected software |
Jakarta Tomcat 5.0.19 Tomcat 4.1.24 Apache Tomcat 5.0.0 <= 5.0.30 Apache Tomcat 5.5.0 <= 5.5.17 Sun Solaris 9 Sun Solaris 10 |
Description |
|
|
Se han encontrado múltiples vulnerabilidades del tipo cross-site scripting en Jakarta Tomcat. Las vulnerabilidades son descritas a continuación. - CVE-2005-2090: Se ha encontrado una vulnerabilidad en Jakarta Tomcat 5.0.19 y Tomcat 4.1.24. La vulnerabilidad reside en un error en el manejo de peticiones HTTP con cabeceras "Transfer Encoding: chunked" y Content-Length. Un atacante remoto podría realizar un ataque del tipo cross-site scripting saltandose restricciones del cortafuegos. - CVE-2006-7195: Se ha encontrado una vulnerabilidad del tipo cross-site scripting en Apache Tomcat en la versión 5.0.0 hasta la 5.0.30 y en la versión 5.5.0 hasta la 5.5.17. Esto es debido a un error no especificado en la librería implicit-objects.jsp. Un atacante remoto podría inyectar código arbitrario del tipo web script o HTML mediante determinadas cabeceras. |
|
Solution |
|
|
Actualización de software Red Hat (RHSA-2007:0327-5) RHEL Desktop Workstation (v. 5 client) Red Hat Enterprise Linux (v. 5 server) Red Hat Enterprise Linux Desktop (v. 5 client) https://rhn.redhat.com/ Red Hat (RHSA-2008:0261-4) Red Hat Network Satellite (v. 5.0 para RHEL 4) https://rhn.redhat.com/ Apple Mac OS 10.3.9 http://www.apple.com/support/downloads/securityupdate20070071039.html Mac OS Server 10.3.9 http://www.apple.com/support/downloads/securityupdate20070071039server.html Mac OS PPC 10.4.10 http://www.apple.com/support/downloads/securityupdate200700710410ppc.html Mac OS Server PPC 10.4.10 http://www.apple.com/support/downloads/securityupdate200700710410serverppc.html Mac OS Universal 10.4.10 http://www.apple.com/support/downloads/securityupdate200700710410universal.html Mac OS Server Universal 10.4.10 http://www.apple.com/support/downloads/securityupdate200700710410serveruniversal.html Suse Linux Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux. Sun (239312) Solaris 10 / SPARC / patch 122911-12 Solaris 10 / x86 / patch 122912-12 http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage |
|
Standar resources |
|
| Property | Value |
| CVE |
CVE-2005-2090 CVE-2006-7195 |
| BID |
25159 13873 |
Other resources |
|
|
Red Hat Security Advisory (RHSA-2007:0327-5) https://rhn.redhat.com/errata/RHSA-2007-0327.html Red Hat Security Advisory (RHSA-2008:0261-4) http://rhn.redhat.com/errata/RHSA-2008-0261.html Apple Security Update (306172) http://docs.info.apple.com/article.html?artnum=306172 SUSE Security Advisory (SUSE-SR:2008:005) http://www.novell.com/linux/security/advisories/2008_5_sr.html Sun Alert Notification (239312) http://sunsolve.sun.com/search/document.do?assetkey=1-66-239312-1 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2007-05-15 |
| 1.1 | Aviso emitido por Apple (306172) | 2007-08-02 |
| 1.2 | Aviso emitido por Suse (SUSE-SR:2008:005) | 2008-03-07 |
| 1.3 | Aviso emitido por Red Hat (RHSA-2008:0261-4) | 2008-05-21 |
| 1.4 | Aviso emitido por Sun (239312). BID añadido. | 2008-07-01 |






