Moderate: tomcat6 (SL6)

Synopsis: Moderate: tomcat6 security update
Advisory ID: SLSA-2013:0964-1
Issue Date: 2013-06-20
CVE Numbers: CVE-2013-2067

A session fixation flaw was found in the Tomcat FormAuthenticator module.
During a narrow window of time, if a remote attacker sent requests while a
user was logging in, it could possibly result in the attacker’s requests
being processed as if they were sent by the user. (CVE-2013-2067)

Tomcat must be restarted for this update to take effect.

SL6
noarch
tomcat6-6.0.24-57.el6_4.noarch.rpm
tomcat6-admin-webapps-6.0.24-57.el6_4.noarch.rpm
tomcat6-docs-webapp-6.0.24-57.el6_4.noarch.rpm
tomcat6-el-2.1-api-6.0.24-57.el6_4.noarch.rpm
tomcat6-javadoc-6.0.24-57.el6_4.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-57.el6_4.noarch.rpm
tomcat6-lib-6.0.24-57.el6_4.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-57.el6_4.noarch.rpm
tomcat6-webapps-6.0.24-57.el6_4.noarch.rpm

– Scientific Linux Development Team