 |
» |
|
|
 |
 |
 |
|
|
 |
|
<TITLE>
TITLE: Internet Express for Tru64 UNIX - SSRT071472: Apache Tomcat, Potential Remote Denial of Service (DoS)
Copyright (c) Hewlett-Packard Company 2007. All rights reserved.
PRODUCT: Tomcat Java Servlet and JSP Engine
SOURCE: Hewlett-Packard Company
ECO INFORMATION:
ECO Name: T64V51B-IX671-TOMCAT5525-SSRT147-20071003
ECO Kit Approximate Size: 18.4MB
Kit Applies To: Internet Express for Tru64 UNIX v 6.7, v 6.6, v 6.5
ECO Kit CHECKSUMS:
/usr/bin/sum results:
63542 17932
/usr/bin/cksum results:
253325787 18361751
MD5 results:
f5219a90e45abe949aebaedcbb43c680
SHA1 results:
6836ce607432e453d246e308a57ef1a6db755bec
ECO KIT SUMMARY:
A setld-based patch kit exists for Internet Express for Tru64 UNIX versions 6.7,
6.6, and 6.5 that contains solutions to the following problem(s):
Multiple vulnerabilities have been reported on Apache Tomcat (Tomcat) running
on HP Internet Express (IX) for Tru64 UNIX v 6.5 and greater. The vulnerabilities
can increase the probability of session hijacking, and under certain circumstances
can
lead to a remote Denial of Service (DoS).
The patches in this kit will also be available in the next mainstream
patch kit - Internet Express for Tru64 UNIX v 6.8.
This patch provides the following:
- Tomcat v 5.5.25
- Tomcat v 5.5.25 sources and license agreement
Special Installation Instructions
The kit is a tar file, that when extracted creates
the directory T64V51B-IX671-TOMCAT5525-SSRT147-20071003 .
This directory contains the following files.
T64V51B-IX671-TOMCAT5525-SSRT147 (Directory - installable kit)
apache-tomcat-5.5.25-src.tar.gz (source-tar)
Before installing the kit, please back-up project-specific conf files.
Make java142 as a default java version, as this kit needs java142
as minimum java version to run.
For kit installation, please follow these instructions:
# gunzip T64V51B-IX671-TOMCAT5525-SSRT147-20071003.tar.gz
# tar xvf T64V51B-IX671-TOMCAT5525-SSRT147-20071003.tar
# cd T64V51B-IX671-TOMCAT5525-SSRT147-20071003
# cd T64V51B-IX671-TOMCAT5525-SSRT147/
# ls
IAE.image IAETOMCAT671 INSTCTRL instctrl
# setld -l . IAETOMCAT671
SUPERSEDE INFORMATION:
None
KNOWN PROBLEMS WITH THE PATCH KIT:
None.
[R] UNIX is a registered trademark in the United States and other countries
licensed exclusively through X/Open Company Limited.
Copyright Hewlett-Packard Company 2007. All Rights reserved.
|