CVE-2015-5345 patch issue on tomcat7

Bug #1609819 reported by Stephen Lynch
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tomcat7 (Ubuntu)
Fix Released
Medium
Unassigned
Trusty
Fix Released
Medium
Marc Deslauriers

Bug Description

7.0.52-1ubuntu0.6 contains the patch for CVE-2015-5345. It adds mapperContextRootRedirectEnabled as a workaround to prevent breaking the current functionality. This fix cannot be used with the current ubuntu patches as it is missing the change to MapperListener.java in revision http://svn.apache.org/viewvc?view=revision&revision=1716860 (bz https://bz.apache.org/bugzilla/show_bug.cgi?id=58765)

Without it, the values specified in context.xml are not passed down to the Mapper.java on startup.

Setting mapperContextRootRedirectEnabled="true" in /etc/tomcat7/context.xml has no effect. Making the same change with 7.0.70 from tomcat.apache.org works perfectly.

CVE References

Robie Basak (racb)
information type: Public → Public Security
Changed in tomcat7 (Ubuntu Trusty):
status: New → Confirmed
assignee: nobody → Marc Deslauriers (mdeslaur)
Changed in tomcat7 (Ubuntu):
status: New → Invalid
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package tomcat7 - 7.0.52-1ubuntu0.7

---------------
tomcat7 (7.0.52-1ubuntu0.7) trusty-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via insecure init script
    - debian/tomcat7.init: don't follow symlinks when handling the
      catalina.out file.
    - CVE-2016-1240
  * SECURITY REGRESSION: change in behaviour after security update
    (LP: #1609819)
    - debian/patches/CVE-2015-5345-2.patch: fix using the new
      mapperContextRootRedirectEnabled option in
      java/org/apache/catalina/connector/MapperListener.java, change
      mapperContextRootRedirectEnabled default to true in
      java/org/apache/catalina/core/StandardContext.java,
      webapps/docs/config/context.xml. This reverts the change in behaviour
      following the CVE-2015-5345 security update and was also done
      upstream in later releases.

 -- Marc Deslauriers <email address hidden> Fri, 16 Sep 2016 09:19:37 -0400

Changed in tomcat7 (Ubuntu Trusty):
status: Confirmed → Fix Released
Mathew Hodson (mhodson)
Changed in tomcat7 (Ubuntu):
status: Invalid → Fix Released
importance: Undecided → Medium
Changed in tomcat7 (Ubuntu Trusty):
importance: Undecided → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.