The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
References
Link Providers
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://osvdb.org/39833 cve-icon cve-icon
http://secunia.com/advisories/28274 cve-icon cve-icon
http://secunia.com/advisories/28317 cve-icon cve-icon
http://secunia.com/advisories/28915 cve-icon cve-icon
http://secunia.com/advisories/29313 cve-icon cve-icon
http://secunia.com/advisories/29711 cve-icon cve-icon
http://secunia.com/advisories/30676 cve-icon cve-icon
http://secunia.com/advisories/32120 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://secunia.com/advisories/32266 cve-icon cve-icon
http://secunia.com/advisories/37460 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200804-10.xml cve-icon cve-icon
http://securityreason.com/securityalert/3485 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-401.htm cve-icon cve-icon
http://svn.apache.org/viewvc?view=rev&revision=606594 cve-icon cve-icon
http://tomcat.apache.org/security-5.html cve-icon cve-icon
http://tomcat.apache.org/security-6.html cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1447 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:188 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0042.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0195.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0831.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0832.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0833.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0834.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0862.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/485481/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/27006 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0010.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0013 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1856/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2823 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/39201 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-5342 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10417 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-5342 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-12-27T22:00:00

Updated: 2024-08-07T15:24:42.402Z

Reserved: 2007-10-10T00:00:00

Link: CVE-2007-5342

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-12-27T22:46:00.000

Modified: 2024-11-21T00:37:41.777

Link: CVE-2007-5342

cve-icon Redhat

Severity : Low

Publid Date: 2007-12-23T00:00:00Z

Links: CVE-2007-5342 - Bugzilla