CVE-2008-2938

Impact:
Moderate
Public Date:
2008-08-11
Bugzilla:
456120: CVE-2008-2938 tomcat Unicode directory traversal vulnerability

The MITRE CVE dictionary describes this issue as:

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

Find out more about CVE-2008-2938 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat Developer Suite v.3 (AS v.4) (tomcat5) RHSA-2008:0864 2008-10-02
Red Hat Enterprise Linux 5 (tomcat5) RHSA-2008:0648 2008-08-27
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat Application Server v2 4AS (tomcat5) RHSA-2008:0862 2008-10-02
Red Hat Satellite 5.0 (RHEL v.4 AS) RHSA-2008:1007 2008-12-08
Red Hat Satellite 5.1 (RHEL v.4 AS) (tomcat5) RHSA-2008:1007 2008-12-08
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS (jbossweb) RHSA-2008:0877 2008-09-22
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS (jbossweb) RHSA-2008:0877 2008-09-22

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.