Bug 1102410 - (CVE-2018-8037) VUL-0: CVE-2018-8037: tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up
(CVE-2018-8037)
VUL-0: CVE-2018-8037: tomcat: Due to a mishandling of close in NIO/NIO2 conne...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Matei Albu
Security Team bot
https://smash.suse.de/issue/211459/
CVSSv3:RedHat:CVE-2018-8037:9.1:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-07-24 11:55 UTC by Johannes Segitz
Modified: 2019-06-06 11:40 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-07-24 11:55:25 UTC
rh#1607582

Flaw affecting tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31. A bug in the tracking of connection closures can lead to reuse of user sessions in a new connection.

Upstream patch:
http://svn.apache.org/viewvc?view=rev&rev=1833906
http://svn.apache.org/viewvc?view=rev&rev=1833907

SLE 15 only

References:
https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-9.html
https://bugzilla.redhat.com/show_bug.cgi?id=1607582
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8037
Comment 5 Swamp Workflow Management 2018-09-13 10:12:47 UTC
SUSE-SU-2018:2699-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1095472,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Server 12-SP3 (src):    tomcat-8.0.53-29.13.1
Comment 6 Swamp Workflow Management 2018-09-17 10:13:41 UTC
openSUSE-SU-2018:2740-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1095472,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
openSUSE Leap 42.3 (src):    tomcat-8.0.53-15.1
Comment 10 Swamp Workflow Management 2018-10-04 22:09:00 UTC
SUSE-SU-2018:3011-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15 (src):    tomcat-9.0.10-3.3.1
Comment 11 Swamp Workflow Management 2018-10-06 16:11:00 UTC
openSUSE-SU-2018:3054-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
openSUSE Leap 15.0 (src):    tomcat-9.0.10-lp150.2.3.2
Comment 13 Swamp Workflow Management 2018-10-24 16:47:05 UTC
SUSE-SU-2018:3388-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481,1093697,1102379,1102400,1102410,1110850
CVE References: CVE-2017-15706,CVE-2018-11784,CVE-2018-1304,CVE-2018-1305,CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    tomcat-8.0.53-10.35.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    tomcat-8.0.53-10.35.1
Comment 14 Swamp Workflow Management 2018-11-28 14:10:30 UTC
SUSE-SU-2018:3011-2: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    tomcat-9.0.10-3.7.1
Comment 15 Marcus Meissner 2019-06-06 11:40:01 UTC
done