SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#993544

Apache Tomcat fails to properly handle cookies containing single quotes

Overview

Apache Tomcat fails to properly handle cookies that contain a single quote, which may allow session hijacking.

I. Description

Apache Tomcat is an implementation of the Java Servlet and JavaServer Page (JSP) technologies. Apache Tomcat incorrectly treats a single quote as a cookie delimiter. This can cause the Tomcat cookie parsing mechanism to improperly handle all of the cookies in the cookie string that follow the cookie with the single quote. According to the vendor, the following versions of Apache Tomcat are affected

    6.0.0 to 6.0.13
    5.5.0 to 5.5.24
    5.0.0 to 5.0.30
    4.1.0 to 4.1.36
    3.3 to 3.3.2

II. Impact

This vulnerability can increase the possibility of a session hijacking success. In the presense of a cross-site scripting vulnerability, it may allow a denial-of-service attack against a web site by preventing a client from being able to log in using cookies.

III. Solution

Apply an update

This vulnerability is addressed in Apache Tomcat 6.0.14. Please check the Apache Tomcat Security page for availability of fixes for this and other versions of Tomcat.

Systems Affected

VendorStatusDate Updated
Apache TomcatVulnerable14-Aug-2007

References


http://tomcat.apache.org/security.html
http://seclists.org/fulldisclosure/2007/Aug/0236.html
http://secunia.com/advisories/26466/

Credit

Thanks to Tomasz Kuczynski for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public08/13/2007
Date First Published08/14/2007 11:04:21 AM
Date Last Updated08/15/2007
CERT Advisory 
CVE-ID(s)CVE-2007-3382
NVD-ID(s)CVE-2007-3382
US-CERT Technical Alerts 
Metric4.61
Document Revision6

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader