Bug 822177 (CVE-2013-1976) - VUL-1: CVE-2013-1976: tomcat: two issues
Summary: VUL-1: CVE-2013-1976: tomcat: two issues
Status: RESOLVED FIXED
Alias: CVE-2013-1976
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Normal
Target Milestone: ---
Deadline: 2013-08-09
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3:53858 maint:...
Keywords:
Depends on:
Blocks: 824284
  Show dependency treegraph
 
Reported: 2013-05-29 09:31 UTC by Matthias Weckbecker
Modified: 2018-08-23 16:07 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2013-05-29 09:31:48 UTC
There are two new CVE regarding tomcat:

  * CVE-2013-2051
  * CVE-2013-1976

Unfortunately, I don't have much more at the moment. Are you guys aware of more
information?
Comment 1 Swamp Workflow Management 2013-05-29 22:00:15 UTC
bugbot adjusting priority
Comment 2 Michal Vyskocil 2013-06-04 07:28:41 UTC
No, actually no one for Apache tomcat security pages mention those CVEs

 * CVE-2013-2071
 * CVE-2013-2067
http://tomcat.apache.org/security-7.html

 * CVE-2013-2067
http://tomcat.apache.org/security-6.html

 * no 2013 CVE
http://tomcat.apache.org/security-5.html
Comment 7 Marcus Meissner 2013-07-18 12:00:15 UTC
from rh bugzilla:

CVE-2013-2051: It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.

(need to review our patch ... update soon)



CVE-2013-1976 tomcat: Improper TOMCAT_LOG management in init script (DoS, ACE)

A security flaw was found in the way init script implementation of the Tomcat service, an Apache Servlet/JSP Engine, as used in various versions of Red Hat Enterprise Linux and Fedora, performed management of Tomcat log file. A local attacker could use this flaw to cause denial of service or, potentially, execute arbitrary code with the privileges of the privileged system user (root) via symbolic link attacks on Tomcat log file.

Evaluation:
Our /var/log/tomcat6 is root:tomcat ... logfile is handled by root in our init script using:
    touch $TOMCAT_LOG
    chown ${TOMCAT_USER}:${TOMCAT_USER} $TOMCAT_LOG


so basically a tomcat group member (attacker that gained tomcat privs) could escalate his privileges to root (by replacing the $TOMCAT_LOG file with a symlink to /etc/passwd.

CHOWN with --no-dereference   would be a hardening start there
)
Comment 8 Marcus Meissner 2013-07-18 13:01:14 UTC
CVE-2013-2051: I think we backported correctly, our fixes in tomcat6 and tomcat6 looks like the upstream. So I would say not affected by CVE-2013-2051.
Comment 11 Bernhard Wiedemann 2013-07-26 14:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/184435 Maintenance / 
https://build.opensuse.org/request/show/184436 Maintenance / 
https://build.opensuse.org/request/show/184437 Factory / tomcat
Comment 12 Swamp Workflow Management 2013-07-26 15:20:47 UTC
The SWAMPID for this issue is 53781.
This issue was rated as moderate.
Please submit fixed packages until 2013-08-09.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 13 Bernhard Wiedemann 2013-07-29 10:00:36 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/184583 Maintenance /
Comment 14 Bernhard Wiedemann 2013-07-30 14:00:27 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/184951 Maintenance / 
https://build.opensuse.org/request/show/184952 Maintenance /
Comment 17 Swamp Workflow Management 2013-08-07 08:04:20 UTC
openSUSE-SU-2013:1306-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 822177,831117
CVE References: CVE-2013-1976,CVE-2013-2071
Sources used:
openSUSE 12.3 (src):    tomcat-7.0.35-2.9.1
Comment 18 Swamp Workflow Management 2013-08-07 08:05:11 UTC
openSUSE-SU-2013:1307-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 768772,804992,822177,831117,831119
CVE References: CVE-2013-1976,CVE-2013-2067,CVE-2013-3544
Sources used:
openSUSE 12.2 (src):    tomcat-7.0.27-2.19.1
Comment 19 Bernhard Wiedemann 2013-08-09 11:00:09 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/186566 Factory / tomcat
Comment 20 Swamp Workflow Management 2013-08-22 22:14:52 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP2 (i386, x86_64)
Comment 21 Swamp Workflow Management 2013-08-22 22:20:18 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 22 Swamp Workflow Management 2013-08-22 22:45:57 UTC
Update released for: tomcat6, tomcat6-admin-webapps, tomcat6-docs-webapp, tomcat6-javadoc, tomcat6-jsp-2_1-api, tomcat6-lib, tomcat6-servlet-2_5-api, tomcat6-webapps
Products:
SLE-SERVER 11-SP1-TERADATA (x86_64)
SUSE-MANAGER 1.2 (x86_64)
Comment 23 Matthias Weckbecker 2013-08-27 10:15:22 UTC
released
Comment 24 Bernhard Wiedemann 2013-08-28 06:01:46 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/196597 Evergreen:11.2 / tomcat6
Comment 25 Swamp Workflow Management 2013-09-08 16:04:58 UTC
openSUSE-SU-2013:1411-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 768772,822177,831117,831119
CVE References: CVE-2012-3544,CVE-2013-1976,CVE-2013-2067
Sources used:
openSUSE 11.4 (src):    tomcat6-6.0.32-42.1
Comment 26 Bernhard Wiedemann 2013-09-11 06:02:23 UTC
This is an autogenerated message for OBS integration:
This bug (822177) was mentioned in
https://build.opensuse.org/request/show/198409 Evergreen:11.2 / tomcat6