UBUNTU-CVE-2013-2067

Source
https://ubuntu.com/security/CVE-2013-2067
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2067.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-2067
Upstream
  • CVE-2013-2067
Related
  • USN-1841-1
Withdrawn
2025-07-18T16:42:51Z
Published
2013-05-10T00:00:00Z
Modified
2026-02-04T04:22:30.289203Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

References

Affected packages

Ubuntu:14.04:LTS / tomcat6

Package

Name
tomcat6
Purl
pkg:deb/ubuntu/tomcat6@6.0.39-1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.39-1

Affected versions

6.*
6.0.37-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libservlet2.4-java",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "libservlet2.5-java",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "libservlet2.5-java-doc",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "libtomcat6-java",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-admin",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-common",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-docs",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-examples",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-extras",
            "binary_version": "6.0.39-1"
        },
        {
            "binary_name": "tomcat6-user",
            "binary_version": "6.0.39-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2067.json"