CVE-2013-1976
Vulnerability Summary
Timeline
Description
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.
CVSS Metrics
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.37%• Percentile: 31%
Techniques & Countermeasures
- CWE-59•Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Affected Systems
- redhat•enterprise_linux
5 | 6.0
- redhat•jboss_enterprise_web_server
1.0.2 | 2.0.0
- redhat•tomcat5
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-admin-webapps
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-common-lib
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-debuginfo
< 0:5.5.23-0jpp.40.el5_9
- redhat•tomcat5-jasper
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-jasper-eclipse
< 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-jasper-javadoc
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-jsp-2.0-api
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-jsp-2.0-api-javadoc
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-parent
< 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-server-lib
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-servlet-2.4-api
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-servlet-2.4-api-javadoc
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat5-webapps
< 0:5.5.23-0jpp.40.el5_9 | < 0:5.5.33-33_patch_09.ep5.el5 | < 0:5.5.33-36_patch_09.ep5.el6
- redhat•tomcat6
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-admin-webapps
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-docs-webapp
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-el-1.0-api
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-javadoc
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-jsp-2.1-api
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-lib
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-log4j
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-servlet-2.5-api
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat6-webapps
< 0:6.0.35-12_patch_07.ep6.el5 | < 0:6.0.35-33_patch_07.ep6.el6 | < 0:6.0.32-32_patch_09.ep5.el5 | < 0:6.0.32-35_patch_09.ep5.el6
- redhat•tomcat7
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-admin-webapps
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-docs-webapp
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-el-1.0-api
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-javadoc
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-jsp-2.2-api
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-lib
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-log4j
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-servlet-3.0-api
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
- redhat•tomcat7-webapps
< 0:7.0.30-5_patch_03.ep6.el5 | < 0:7.0.30-7_patch_03.ep6.el6
References (16)
- http://rhn.redhat.com/errata/RHSA-2013-0871.html
- http://rhn.redhat.com/errata/RHSA-2013-0869.html
- https://bugzilla.redhat.com/show_bug.cgi?id=927622
- http://rhn.redhat.com/errata/RHSA-2013-0870.html
- http://rhn.redhat.com/errata/RHSA-2013-0872.html
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00013.html
- https://access.redhat.com/errata/RHSA-2013:0870
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0870.json
- https://access.redhat.com/security/cve/CVE-2013-1976
- https://www.cve.org/CVERecord?id=CVE-2013-1976
- https://nvd.nist.gov/vuln/detail/CVE-2013-1976
- https://access.redhat.com/errata/RHSA-2013:0871
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0871.json
- https://access.redhat.com/errata/RHSA-2013:0872
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0872.json