Tomcat: Multiple vulnerabilities Multiple vulnerabilities in Tomcat may lead to local file overwriting, session hijacking or information disclosure. tomcat April 10, 2008 May 28, 2009: 02 196066 203169 local, remote 5.5.26 6.0.16 5.5.27 6.0.16

Tomcat is the Apache Jakarta Project's official implementation of Java Servlets and Java Server Pages.

The following vulnerabilities were reported:

These vulnerabilities can be exploited by:

There is no known workaround at this time.

All Tomcat 5.5.x users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-5.5.26"

All Tomcat 6.0.x users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-6.0.16"
CVE-2007-5333 CVE-2007-5342 CVE-2007-5461 CVE-2007-6286 CVE-2008-0002 rbu mfleming p-y