CVE-2007-5333
Publication date 12 February 2008
Last updated 24 July 2024
Ubuntu priority
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat5 | ||
tomcat5.5 | ||