CVE-2008-0128
| Name | CVE-2008-0128 |
| Source | CVE (at NVD; RH) |
| Description | The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. |
| References | DSA-1468-1 |
| NVD severity | medium (attack range: remote) |
| Debian/oldstable | not vulnerable. |
| Debian/stable | not known to be vulnerable. |
| Debian/testing | not known to be vulnerable. |
| Debian/unstable | not known to be vulnerable. |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| tomcat5.5 (PTS) | lenny, lenny (security) | 5.5.26-5lenny2 | fixed |
The information above is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| tomcat5 | source | (unstable) | (unfixed) | unimportant | | |
| tomcat5.5 | source | (unstable) | 5.5.23-1 | low | | |
| tomcat5.5 | source | etch | 5.5.20-2etch2 | medium | DSA-1468-1 | |
Notes
SSO cookies not working in 5.0, have only been fixed in 5.5.13, see #34724
SSO cookies sent over secure connections do not require
secure connections, possibly defeating HTTPS encryption.
See: http://issues.apache.org/bugzilla/show_bug.cgi?id=41217
Home - Testing Security Team - Debian Security - Imprint