CVE-2008-0128

NameCVE-2008-0128
SourceCVE (at NVD; RH)
DescriptionThe SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
ReferencesDSA-1468-1
NVD severitymedium (attack range: remote)
Debian/oldstablenot vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat5.5 (PTS)lenny, lenny (security)5.5.26-5lenny2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat5source(unstable)(unfixed)unimportant
tomcat5.5source(unstable)5.5.23-1low
tomcat5.5sourceetch5.5.20-2etch2mediumDSA-1468-1

Notes

SSO cookies not working in 5.0, have only been fixed in 5.5.13, see #34724
SSO cookies sent over secure connections do not require
secure connections, possibly defeating HTTPS encryption.
See: http://issues.apache.org/bugzilla/show_bug.cgi?id=41217

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint