On The Insider: Cyrus FamilyOn the Loss of Bus Driver
BNET Business Network:
BNET
TechRepublic
ZDNet

August 21st, 2008

Exploit code published for Apache Tomcat flaw

Posted by Ryan Naraine @ 9:22 am

Categories: Anti Virus, Arbitrary Code Execution, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Hackers, Locally Running Web Servers, Malware, Open source, Passwords, Patch Watch, Pen testing, Phishing, Privacy, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: HTTP, XSS, Apache Software Foundation, Exploit Code, Apache Tomcat, Flaw, Open Source, Application Servers, Middleware, Enterprise Software

Exploit code published for Apache Tomcat flawThe United States Computer Emergency Response Team (US-CERT) has raised an alarm for a serious vulnerability in Apache Tomcat, warning that a proof-of-concept exploit is publicly available.

The code, posted to Milw0rm.com, exploits a directory traversal vulnerability vulnerability in the way Apache Tomcat handles malformed requests.

From the advisory:

  • If a context is configured with allowLinking=”true” and the connector is configured with URIEncoding=”UTF-8″ then a malformed request may be used to access arbitrary files on the server.

The vulnerability (CVE-2008-2938) affects Apache Tomcat versions 4.1.0-4.1.37, 5.5.0-5.5.26, and 6.0.0-6.0.16.

The open-source group has shipped a fix in Apache Tomcat 6.0.18, an update that also fixes three additional security issues:

CVE-2008-1232 (cross-site scripting): The message argument of HttpServletResponse.sendError() call is not only displayed on the error page, but is also used for the reason-phrase of HTTP response. This may include characters that are illegal in HTTP headers. It is possible for a specially crafted message to result in arbitrary content being injected into the HTTP response. For a successful XSS attack, unfiltered user supplied data must be included in the message argument. This affects 6.0.0 - 6.0.16

CVE-2008-1947 (cross-site scripting): The Host Manager web application did not escape user provided data before including it in the output. This enabled a XSS attack. This application now filters the data before use. This issue may be mitigated by logging out (closing the browser) of the application once the management tasks have been completed.

CVE-2008-2370 (information disclosure): When using a RequestDispatcher the target path was normalised before the query string was removed. A request that included a specially crafted request parameter could be used to access content that would otherwise be protected by a security constraint or by locating it in under the WEB-INF directory. This affects: 6.0.0 - 6.0.16.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 12 Talkback(s)
Anyone who calls Apache a "toy"...
...is either a troll or completely ignorant.
How stupid do you have to be to think that the vast majority of web traffic comes from a "toy"?... (Read the rest)
Posted by: bmerc Posted on: 08/22/08 You are currently: a Guest | | Terms of Use
and just how long will it take to get 98% of these servers patched?  dragon@... | 08/21/08
What are you talking about?  bjbrock | 08/21/08
F/OSS vs. Proprietary...  Confused by religion | 08/21/08
Just another ASSumption...  storm14k | 08/21/08
How about...quicker than these?!!  techboy_z | 08/21/08
How many exploits are out there for IIS mean while?  LBiege | 08/21/08
Thanks to Apache...  storm14k | 08/21/08
Nothing like unsubstantiated FUD  tonymcs@... | 08/21/08
I see you like second place...  storm14k | 08/22/08
Anyone who calls Apache a "toy"...  bmerc | 08/22/08
Pfff.. does that matter?  TedKraan | 08/22/08
Nobody  storm14k | 08/22/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More