---
title: "CVE-2013-2067\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-2067?format=md
keywords: index, follow
---

# CVE-2013-2067

Publication date 10 May 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form
authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x
before 7.0.33 does not properly handle the relationships between
authentication requirements and sessions, which allows remote attackers to
inject a request into a session by sending this request during completion
of the login form, a variant of a session fixation attack.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not affected |
| 13.10 saucy | Not affected |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Fixed 6.0.35-5ubuntu0.1 |
| 12.04 LTS precise | Fixed 6.0.35-1ubuntu3.3 |
| 10.04 LTS lucid | Fixed 6.0.24-2ubuntu1.13 |
| tomcat7 | 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not affected |
| 13.10 saucy | Not affected |
| 13.04 raring | Not affected |
| 12.10 quantal | Fixed 7.0.30-0ubuntu1.2 |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2013-2067?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| tomcat6 | * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1417891> |
| tomcat7 | * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1408044> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2067)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-2067)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-2067)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-2067)

### Related Ubuntu Security Notices (USN)

+ [USN-1841-1](https://usn.ubuntu.com/USN-1841-1)
+ Tomcat vulnerabilities
+ 28 May 2013

### Other references

* <http://mail-archives.apache.org/mod_mbox/tomcat-announce/201305.mbox/%3C518CB1D4.1020106@apache.org%3E>
* <http://tomcat.apache.org/security-6.html>
* <http://tomcat.apache.org/security-7.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-2067>
