Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-5333

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2007-5333
Last Modified 15 Mar 2014 11:16:41
Published 11 Feb 2008 08:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-5333

Summary

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

Vulnerable Systems

Application

  • Apache Software Foundation Tomcat 4.1

  • Apache Software Foundation Tomcat 4.1.32

  • Apache Software Foundation Tomcat 4.1.34

  • Apache Software Foundation Tomcat 4.1.37

  • Apache Software Foundation Tomcat 5.0

  • Apache Software Foundation Tomcat 5.1

  • Apache Software Foundation Tomcat 5.2

  • Apache Software Foundation Tomcat 5.3

  • Apache Software Foundation Tomcat 5.4

  • Apache Software Foundation Tomcat 5.5

  • Apache Tomcat 4.1.10

  • Apache Tomcat 4.1.12

  • Apache Tomcat 4.1.24

  • Apache Tomcat 4.1.3

  • Apache Tomcat 4.1.31

  • Apache Tomcat 4.1.36

  • Apache Tomcat 4.1.9

  • Apache Tomcat 5.0.1

  • Apache Tomcat 5.0.10

  • Apache Tomcat 5.0.11

  • Apache Tomcat 5.0.12

  • Apache Tomcat 5.0.13

  • Apache Tomcat 5.0.14

  • Apache Tomcat 5.0.15

  • Apache Tomcat 5.0.16

  • Apache Tomcat 5.0.19

  • Apache Tomcat 5.0.2

  • Apache Tomcat 5.0.28

  • Apache Tomcat 5.0.3

  • Apache Tomcat 5.0.30

  • Apache Tomcat 5.0.4

  • Apache Tomcat 5.0.5

  • Apache Tomcat 5.0.6

  • Apache Tomcat 5.0.7

  • Apache Tomcat 5.0.8

  • Apache Tomcat 5.0.9

  • Apache Tomcat 5.5.1

  • Apache Tomcat 5.5.10

  • Apache Tomcat 5.5.11

  • Apache Tomcat 5.5.12

  • Apache Tomcat 5.5.13

  • Apache Tomcat 5.5.14

  • Apache Tomcat 5.5.15

  • Apache Tomcat 5.5.16

  • Apache Tomcat 5.5.17

  • Apache Tomcat 5.5.18

  • Apache Tomcat 5.5.19

  • Apache Tomcat 5.5.2

  • Apache Tomcat 5.5.20

  • Apache Tomcat 5.5.21

  • Apache Tomcat 5.5.22

  • Apache Tomcat 5.5.23

  • Apache Tomcat 5.5.24

  • Apache Tomcat 5.5.25

  • Apache Tomcat 5.5.3

  • Apache Tomcat 5.5.4

  • Apache Tomcat 5.5.5

  • Apache Tomcat 5.5.6

  • Apache Tomcat 5.5.7

  • Apache Tomcat 5.5.8

  • Apache Tomcat 5.5.9

  • Apache Tomcat 6.0

  • Apache Tomcat 6.0.1

  • Apache Tomcat 6.0.10

  • Apache Tomcat 6.0.11

  • Apache Tomcat 6.0.12

  • Apache Tomcat 6.0.13

  • Apache Tomcat 6.0.14

  • Apache Tomcat 6.0.15

  • Apache Tomcat 6.0.2

  • Apache Tomcat 6.0.3

  • Apache Tomcat 6.0.4

  • Apache Tomcat 6.0.5

  • Apache Tomcat 6.0.6

  • Apache Tomcat 6.0.7

  • Apache Tomcat 6.0.8

  • Apache Tomcat 6.0.9


References

BID - 27706

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=532111

VUPEN - ADV-2009-3316

VUPEN - ADV-2008-2780

VUPEN - ADV-2008-2690

VUPEN - ADV-2008-1981

VUPEN - ADV-2008-1856

VUPEN - ADV-2008-0488

CONFIRM - http://www.vmware.com/security/advisories/VMSA-2009-0016.html

CONFIRM - http://www.vmware.com/security/advisories/VMSA-2008-0010.html

BID - 31681

BUGTRAQ - 20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

BUGTRAQ - 20080208 [SECURITY] CVE-2007-5333: Tomcat Cookie handling vulnerabilities

CONFIRM - http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp08/html-single/Release_Notes/index.html

MANDRIVA - MDVSA-2010:176

MANDRIVA - MDVSA-2009:018

AIXAPAR - IZ20991

AIXAPAR - IZ20133

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg27012048

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg27012047

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg24018932

CONFIRM - http://tomcat.apache.org/security-6.html

CONFIRM - http://tomcat.apache.org/security-5.html

CONFIRM - http://tomcat.apache.org/security-4.html

CONFIRM - http://support.apple.com/kb/HT3216

CONFIRM - http://support.apple.com/kb/HT2163

SECUNIA - 44183

SECUNIA - 37460

SECUNIA - 33330

SECUNIA - 32222

SECUNIA - 32036

SECUNIA - 30802

SECUNIA - 30676

SUSE - SUSE-SR:2009:004

APPLE - APPLE-SA-2008-10-09

APPLE - APPLE-SA-2008-06-30

FEDORA - FEDORA-2008-1603

FEDORA - FEDORA-2008-1467

SREASON - 3636

GENTOO - GLSA-200804-10

SECUNIA - 29711

SECUNIA - 28915

SECUNIA - 28884

SECUNIA - 28878

JVN - JVN#09470767

HP - HPSBST02955

SECUNIA - 57126

Related Patches

Apple 2008-06-30 Security Update 2008-004 (PPC)

Apple 2008-06-30 Security Update 2008-004 Server (PPC)

Apple 2008-06-30 Security Update 2008-004 (Intel)

Apple 2008-06-30 Security Update 2008-004 Server (Intel)

Apple 2008-10-09 Security Update 2008-007 Server (Leopard)


Last Updated: 27 May 2016 11:04:36