The vendor explicitly identifies these products as affected by this CVE.
- tomcat6 as a component of Red Hat Enterprise Linux 6
- tomcat6-admin-webapps as a component of Red Hat Enterprise Linux 6
- tomcat6-docs-webapp as a component of Red Hat Enterprise Linux 6
- tomcat6-el-2.1-api as a component of Red Hat Enterprise Linux 6
- tomcat6-javadoc as a component of Red Hat Enterprise Linux 6
- tomcat6-jsp-2.1-api as a component of Red Hat Enterprise Linux 6
- tomcat6-lib as a component of Red Hat Enterprise Linux 6
- tomcat6-log4j as a component of Red Hat Enterprise Linux 6
- tomcat6-servlet-2.5-api as a component of Red Hat Enterprise Linux 6
- tomcat6-webapps as a component of Red Hat Enterprise Linux 6
- tomcat6.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the tomcat package. When a web application sends a WebSocket message concurrently with the WebSocket connection closing, the application may continue to use the socket after it has been closed. In this case, the error handling triggered could cause the pooled object to be placed in the pool twice. This issue results in subsequent connections using the same object concurrently, which causes data to be potentially returned to the wrong user or application stability issues.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
