Secunia Logo
 
CVE Reference: CVE-2007-5333
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5333

Description:
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/3636

SAID
  Secunia Advisory: SA30676
  Secunia Advisory: SA28878
  Secunia Advisory: SA28884
  Secunia Advisory: SA28915
  Secunia Advisory: SA29711
  Secunia Advisory: SA30802
  Secunia Advisory: SA32036
  Secunia Advisory: SA32222

JVN
  http://jvn.jp/jp/JVN%2309470767/index.html

GENTOO
  http://security.gentoo.org/glsa/glsa-200804-10.xml

FEDORA

CONFIRM
  http://support.apple.com/kb/HT2163
  http://www-01.ibm.com/support/docview.wss?uid=swg24018932
  http://support.apple.com/kb/HT3216
  http://www.vmware.com/security/advisories/VMSA-2008-0010.html
  http://tomcat.apache.org/security-5.html
  http://tomcat.apache.org/security-6.html
  http://tomcat.apache.org/security-4.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/487822/100/0/threaded

BID
  27706
  31681

APPLE
  http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
  http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html

AIXAPAR
  http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20991


Return to the previous page.