CVE-2008-5515

NameCVE-2008-5515
DescriptionApache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2207-1
Debian Bugs532362, 532363, 532366

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat6 (PTS)jessie, jessie (lts)6.0.45+dfsg-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat5source(unstable)(unfixed)532363
tomcat5.5sourcelenny5.5.26-5lenny2DSA-2207-1
tomcat5.5source(unstable)(unfixed)532366
tomcat6sourcelenny(not affected)
tomcat6source(unstable)6.0.20-1532362

Notes

[lenny] - tomcat6 <not-affected> (Only ships the servlet package)

Search for package or bug name: Reporting problems