tomcat6: CVE-2014-7810: Security Manager bypass by expression language

Related Vulnerabilities: CVE-2014-7810  

Debian Bug report logs - #787010
tomcat6: CVE-2014-7810: Security Manager bypass by expression language

version graph

Reported by: Santiago Ruano Rincón <santiagorr@riseup.net>

Date: Wed, 27 May 2015 18:06:01 UTC

Severity: normal

Tags: fixed-upstream, patch, security, upstream

Found in versions tomcat6/6.0.35-1, tomcat6/6.0.41-1, tomcat6/6.0.41-2+squeeze6

Fixed in version tomcat6/6.0.41-3

Done: Emmanuel Bourg <ebourg@apache.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#787010; Package src:tomcat6. (Wed, 27 May 2015 18:06:06 GMT) (full text, mbox, link).


Acknowledgement sent to Santiago Ruano Rincón <santiagorr@riseup.net>:
New Bug report received and forwarded. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Wed, 27 May 2015 18:06:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Santiago Ruano Rincón <santiagorr@riseup.net>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Cc: Debian LTS <debian-lts@lists.debian.org>
Subject: tomcat6: CVE-2014-7810: Security Manager bypass by expression language
Date: Wed, 27 May 2015 20:03:02 +0200
[Message part 1 (text/plain, inline)]
Source: tomcat6
Version: 6.0.41-2+squeeze6
Severity: normal
Tags: security patch upstream fixed-upstream

Dear Debian Java maintainers,

The Tomcat security team has identified a security issue [cve] that
allows malicious web applications to bypass the Security Manager, by the
use of expression language. The code related to this vulnerability is
present in squeeze and wheezy.

I have prepared the attached patches for squeeze, based on [fix].

[cve] https://security-tracker.debian.org/tracker/CVE-2014-7810
[fix] http://svn.apache.org/viewvc?view=revision&revision=1645366
      http://svn.apache.org/viewvc?view=revision&revision=1659538

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Please adjust the affected versions in the BTS as needed.

Cheers!

Santiago

P.S. This is part of my first security bug reports against tomcat.
Please let me know how can I improve them.
[CVE-2014-7810-1.patch (text/x-diff, attachment)]
[CVE-2014-7810-2.patch (text/x-diff, attachment)]
[signature.asc (application/pgp-signature, inline)]

Marked as found in versions tomcat6/6.0.41-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 27 May 2015 18:24:04 GMT) (full text, mbox, link).


Marked as found in versions tomcat6/6.0.35-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 27 May 2015 18:24:09 GMT) (full text, mbox, link).


Marked as fixed in versions tomcat6/6.0.41-3. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 27 May 2015 18:24:10 GMT) (full text, mbox, link).


Marked Bug as done Request was from Emmanuel Bourg <ebourg@apache.org> to control@bugs.debian.org. (Thu, 21 Jul 2016 10:36:03 GMT) (full text, mbox, link).


Notification sent to Santiago Ruano Rincón <santiagorr@riseup.net>:
Bug acknowledged by developer. (Thu, 21 Jul 2016 10:36:04 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 19 Aug 2016 07:26:12 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 16:52:16 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.